<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2015-09-03T11:04:52.159-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:9701" version="5" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a singleton Unicode sequence in a character class in a regex pattern, which is incorrectly optimized.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4768" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4768"/>
        <description>Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to execute arbitrary code via a singleton Unicode sequence in a character class in a regex pattern, which is incorrectly optimized.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:08.525-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:13:32.858-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:14:38.320-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9701 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:41:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:43:29.676-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:09.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than or equal 9.0.48.0" test_ref="oval:org.mitre.oval:tst:114747"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader /8.x Version">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criterion comment="Check if the version of Adobe Reader is less than 8.1.2" test_ref="oval:org.mitre.oval:tst:141028"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader / 7.x Version">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criterion comment="Check if the version of Adobe Reader is less than 7.1.0" test_ref="oval:org.mitre.oval:tst:140667"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat/ 8.x Version">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criterion comment="Check if the version of Adobe Acrobat is less than 8.1.2" test_ref="oval:org.mitre.oval:tst:140475"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat / 7.x Version">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criterion comment="Check if the version of Adobe Acrobat is less than 7.1.0" test_ref="oval:org.mitre.oval:tst:141084"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 9.0.48.0" test_ref="oval:org.mitre.oval:tst:122611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9250" version="5" class="vulnerability">
      <metadata>
        <title>The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5275"/>
        <description>The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:07.797-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:11:25.703-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:12:26.906-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:9250 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:41:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:43:30.973-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:09.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="AND" comment="Flash.ocx vulnerable version">
            <criterion comment="Determine if the version of Flash.ocx is less than or equal 9.0.124.0" test_ref="oval:org.mitre.oval:tst:122840"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than or equal 9.0.124.0" test_ref="oval:org.mitre.oval:tst:115017"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if the version of Adobe Air is less than 1.0.1" test_ref="oval:org.mitre.oval:tst:141102"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8711" version="12" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Image Preloading Content-Policy Check Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0168"/>
        <description>The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:00.101-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:51.571-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:34.271-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:23.933-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:18.102-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:57.321-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:04.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8711 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:35.729-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:25.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:22.849-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:40.171-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8704" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195"/>
        <description>The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:16.253-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:54.531-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:33.469-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:06.139-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:58.865-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:01.400-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:31.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.12" test_ref="oval:org.mitre.oval:tst:20200"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8703" version="12" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 'multipart/x-mixed-replace' Image Remote Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0164"/>
        <description>Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:55:59.674-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:51.299-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:33.947-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:05.841-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:17.729-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:57.123-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:04.166-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8703 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:25.971-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.954-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.827-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:39.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8697" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Null Pointer Dereference Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0188"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-04T12:37:19.626-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:21.228-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:50.575-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.894-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:38.788-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:46.947-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:58.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:52.583-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:13.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:30.231-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:09.386-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:34.561-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:33.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20618"/>
            <criterion comment="Adobe Reader library is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20886"/>
            <criterion comment="Adobe Reader library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:21083"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20398"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8695" version="7" class="vulnerability">
      <metadata>
        <title>Apache HTTP Server request header information disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0434"/>
        <description>The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-04T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:13.837-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:54.213-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:33.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:05.502-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:57.951-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:01.272-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:31.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.15" test_ref="oval:org.mitre.oval:tst:21012"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8690" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy_balancer' Invalid bb Variable Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6422"/>
        <description>The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:17.652-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:53.847-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:32.874-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:02.733-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:57.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.094-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:31.203-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.8" test_ref="oval:org.mitre.oval:tst:21067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8662" version="8" class="vulnerability">
      <metadata>
        <title>Apache mod_proxy_ftp Module Insufficient Input Validation Access Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095"/>
        <description>The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:15.161-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12000 - Added beginning anchor to the key pattern match" date="2010-05-13T15:36:00.402-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:53.526-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:32.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12000 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:46.772-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:57.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.731-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:31.050-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Apache HTTP Server 2.0.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8605"/>
          <criterion comment="The version of libhttpd.dll is less than 2.0.64" test_ref="oval:org.mitre.oval:tst:21065"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
          <criterion comment="The version of libhttpd.dll is less than 2.2.14" test_ref="oval:org.mitre.oval:tst:21129"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8651" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy_balancer' Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6421"/>
        <description>Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:17.432-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:53.223-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:32.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:04.584-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:56.712-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.911-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:30.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.8" test_ref="oval:org.mitre.oval:tst:21067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8632" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_deflate' Connection State Denial Of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891"/>
        <description>The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:15.971-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:52.861-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:31.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:04.290-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:56.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.839-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:30.680-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.12" test_ref="oval:org.mitre.oval:tst:20200"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8631" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey XSS hazard using SVG document and binary Content-Type</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0162"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-04T12:37:21.764-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:20.583-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:48.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:32.379-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:17.355-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:27.440-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:24.894-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8631 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:35.573-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.618-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6715 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:01.535-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:04.055-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8631 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:28.135-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:13.438-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:39.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8619" version="7" class="vulnerability">
      <metadata>
        <title>Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408"/>
        <description>The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:14.302-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:52.576-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:31.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:03.064-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:56.010-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.156-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:30.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.15" test_ref="oval:org.mitre.oval:tst:21012"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8617" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0257"/>
        <description>Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:03.620-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:46.285-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:29.924-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:00.793-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:43.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Vulnerable Excel 2002">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6860.0" test_ref="oval:org.mitre.oval:tst:20982"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8616" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy' Remote Denial Of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890"/>
        <description>The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:15.758-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:52.298-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:31.378-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:01.786-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:55.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:24:59.939-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:30.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.12" test_ref="oval:org.mitre.oval:tst:20200"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8615" version="20" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and SeaMonkey Use-After-Free HTML Parser Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1571"/>
        <description>Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-04T12:37:22.658-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:20.221-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:45.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:25.490-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:16.890-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:34.857-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:24.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8615 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:45.452-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.462-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6715 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:01.649-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:03.685-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:15.714-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8615 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:8615 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:30.227-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:11.989-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8615 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:05.798-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:39.626-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.2" test_ref="oval:org.mitre.oval:tst:114991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8610" version="21" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/Seamonkey Multiple Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0167"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:01.669-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:45.260-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:29.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:29.964-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:16.450-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:38.960-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:23.875-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8610 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:04.471-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.288-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:57.208-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:03.556-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:16.698-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8610 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:8610 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:29.982-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:12.977-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8610 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:06.715-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:39.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.2" test_ref="oval:org.mitre.oval:tst:114991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8602" version="12" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 'window.location' Same Origin Policy Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0170"/>
        <description>Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:55:59.867-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:42.349-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:26.741-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:15.832-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:16.110-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:56.734-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:03.046-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8602 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:33.804-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:17.295-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:39.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8595" version="10" class="vulnerability">
      <metadata>
        <title>Movie Maker and Producer Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Movie Maker 2.1</product>
          <product>Movie Maker 2.6</product>
          <product>Movie Maker 6.0</product>
          <product>Microsoft Producer 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0265"/>
        <description>Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:12.438-05:00">DRAFT</status_change>
            <modified date="2010-05-05T12:00:00.000-05:00" comment="Added criteria for Microsoft Producer 2003">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-05-05T12:00:00.000-05:00">INTERIM</status_change>
            <status_change date="2010-05-24T04:00:04.994-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:49.140-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:56.641-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:24.051-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:29.788-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8595 - extended definitions of OS are without SP checks" date="2014-07-28T17:51:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:52:51.029-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:37.887-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8595 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:35:00.796-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:37:49.036-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:01:11.045-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Movie Maker 2.1 on Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Movie Maker 2.1 is installed" definition_ref="oval:org.mitre.oval:def:28164"/>
          <criterion comment="Moviemk.exe version is less than 2.1.4027.0" test_ref="oval:org.mitre.oval:tst:21003"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 2.1 on Microsoft Windows XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <extend_definition comment="Windows Movie Maker 2.1 is installed" definition_ref="oval:org.mitre.oval:def:28164"/>
          <criteria operator="OR" comment="file version">
            <criterion comment="Wmoviemk.exe version is less than 2.1.4030.0" test_ref="oval:org.mitre.oval:tst:20887"/>
            <criterion comment="Moviemk.exe version is less than 2.1.4030.0" test_ref="oval:org.mitre.oval:tst:21037"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 6.0 on Microsoft Windows Vista x86/x64 - GDR">
          <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:org.mitre.oval:def:28725"/>
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Moviemk.dll version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:21014"/>
          <criterion comment="Moviemk.dll version is less than 6.0.6000.16937" test_ref="oval:org.mitre.oval:tst:20978"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 6.0 on Microsoft Windows Vista x86/x64 - LDR">
          <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:org.mitre.oval:def:28725"/>
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Moviemk.dll version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:21119"/>
          <criterion comment="Moviemk.dll version is less than 6.0.6000.21139" test_ref="oval:org.mitre.oval:tst:20898"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 6.0 on Microsoft Windows Vista x86/x64 - GDR">
          <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:org.mitre.oval:def:28725"/>
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Moviemk.dll version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:20954"/>
          <criterion comment="Moviemk.dll version is less than 6.0.6001.18341" test_ref="oval:org.mitre.oval:tst:20135"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 6.0 on Microsoft Windows Vista x86/x64 - LDR">
          <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:org.mitre.oval:def:28725"/>
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Moviemk.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:20860"/>
          <criterion comment="Moviemk.dll version is less than 6.0.6001.22541" test_ref="oval:org.mitre.oval:tst:21045"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 6.0 on Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:org.mitre.oval:def:28725"/>
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Moviemk.dll version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20315"/>
          <criterion comment="Moviemk.dll version is less than 6.0.6002.18121" test_ref="oval:org.mitre.oval:tst:21118"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 6.0 on Microsoft Windows Vista x86/x64 - LDR">
          <extend_definition comment="Windows Movie Maker 6.0 is installed" definition_ref="oval:org.mitre.oval:def:28725"/>
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Moviemk.dll version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21108"/>
          <criterion comment="Moviemk.dll version is less than 6.0.6002.22245" test_ref="oval:org.mitre.oval:tst:20993"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Movie Maker 2.6 on Microsoft Windows Vista, Windows 7">
          <criteria operator="OR" comment="Windows Vista, Windows 7">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Windows Movie Maker 2.6 is installed" definition_ref="oval:org.mitre.oval:def:8694"/>
          <criterion comment="Moviemk.exe version is less than 2.6.4038.0" test_ref="oval:org.mitre.oval:tst:20750"/>
        </criteria>
        <extend_definition comment="Microsoft Producer 2003 is installed" definition_ref="oval:org.mitre.oval:def:7279"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8694" version="2" class="inventory">
      <metadata>
        <title>Windows Movie Maker 2.6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Movie Maker 2.6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_movie_maker:2.6"/>
        <description>Windows Movie Maker 2.6 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:12.269-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:50.374-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:33.712-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Movie Maker 2.6 is installed" test_ref="oval:org.mitre.oval:tst:20726"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7279" version="7" class="inventory">
      <metadata>
        <title>Microsoft Producer 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft PowerPoint 2002</product>
          <product>Microsoft PowerPoint 2003</product>
          <product>Microsoft PowerPoint 2007</product>
          <product>Microsoft PowerPoint 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:producer:2003"/>
        <description>The application Microsoft Producer 2003 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-30T14:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-05-05T17:59:49.185-04:00">DRAFT</status_change>
            <status_change date="2010-05-24T04:00:03.913-04:00">INTERIM</status_change>
            <status_change date="2010-06-14T04:00:42.173-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:911 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:14.098-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:30.406-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:911 - new inventory and platforms for MySQL 5.6" date="2014-09-11T08:17:00.634-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-11T08:19:29.463-04:00">INTERIM</status_change>
            <status_change date="2014-09-29T04:00:27.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Producer 2003 is installed" test_ref="oval:org.mitre.oval:tst:11362"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28725" version="3" class="inventory">
      <metadata>
        <title>Windows Movie Maker 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Movie Maker 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_movie_maker:6.0"/>
        <description>Windows Movie Maker 6.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-06-10T14:07:26.434-04:00">DRAFT</status_change>
            <status_change date="2015-06-29T04:00:07.206-04:00">INTERIM</status_change>
            <status_change date="2015-07-20T04:00:10.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Movie Maker 6.0 is installed" test_ref="oval:org.mitre.oval:tst:138739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28164" version="3" class="inventory">
      <metadata>
        <title>Windows Movie Maker 2.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Movie Maker 2.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_movie_maker:2.1"/>
        <description>Windows Movie Maker 2.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-06-10T14:07:27.085-04:00">DRAFT</status_change>
            <status_change date="2015-06-29T04:00:05.168-04:00">INTERIM</status_change>
            <status_change date="2015-07-20T04:00:08.601-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Movie Maker 2.1 is installed" test_ref="oval:org.mitre.oval:tst:138931"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8562" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0262"/>
        <description>Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:04.453-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:38.723-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:23.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:13.064-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:43.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Vulnerable Excel 2007">
        <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
        <criterion comment="Excel.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20930"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8553" version="12" class="vulnerability">
      <metadata>
        <title>HTML Element Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0494"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:26.751-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:51.165-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:30.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:46.442-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:06.318-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:21.521-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.559-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:27.730-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8553 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.639-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:37.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8545" version="9" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel Sheet Object Type Confusion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0258"/>
        <description>Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:03.249-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:35.903-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:20.879-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:17.300-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:55.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:59.582-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:40.509-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:08.566-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:29.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6860.0" test_ref="oval:org.mitre.oval:tst:20982"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8320.0" test_ref="oval:org.mitre.oval:tst:20824"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20930"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20847"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6529.5000" test_ref="oval:org.mitre.oval:tst:21005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8539" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat U3D Support Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3959" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3959"/>
        <description>Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:12.450-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:39.904-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:12.476-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:05.353-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:38.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:28.940-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:54.716-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:10.002-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:12.941-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:46.693-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:08.735-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:56.359-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:32.935-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8538" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4003"/>
        <description>Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-20T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:05.132-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:18.586-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:31.113-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.187-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:37.829-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.6.606" test_ref="oval:org.mitre.oval:tst:21023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8528" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat DLL Loading in 3D Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3954" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3954"/>
        <description>The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vectors, related to a "DLL-loading vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:10.953-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:39.490-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:11.905-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:11.031-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:37.779-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:54.658-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:54.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:39.578-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:12.250-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:12.955-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:08.125-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:48.822-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:32.263-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8524" version="3" class="vulnerability">
      <metadata>
        <title>SMB Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0021"/>
        <description>Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:57.317-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:30.356-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:19.475-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:20.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8523" version="13" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.0 and SeaMonkey Remote Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3981"/>
        <description>Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:53.861-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:29.890-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:13.011-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:02.463-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:15.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:46.631-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:23.451-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8523 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:15.845-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.142-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8523 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:30.179-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:16.809-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:39.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8518" version="27" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player, Acrobat, Adobe Reader and AIR Cross Domain Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0186"/>
        <description>Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-02-15T10:50:44.793-05:00">DRAFT</status_change>
            <status_change date="2010-03-08T04:00:16.693-05:00">INTERIM</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:6598" date="2010-03-22T10:44:00.040-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:32.650-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.337-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:37.198-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:44.296-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:53.551-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:39.208-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:11.526-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:05.296-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:07.233-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:50.319-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:49.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:29.547-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:31.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:19.051-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:58.074-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:20.143-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8518 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:38.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8518 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:41:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:43:27.868-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:08.790-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than or equal 1.5.3.9120" test_ref="oval:org.mitre.oval:tst:21062"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20618"/>
            <criterion comment="Adobe Reader library is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20886"/>
            <criterion comment="Adobe Reader library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:21083"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20398"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8510" version="3" class="vulnerability">
      <metadata>
        <title>MySQL 5.0 and 5.1 Clients with OpenSSL Vulnerability Allows Bypassing Server Certificate Checking</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 5.0</product>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4028"/>
        <description>The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-22T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-27T13:49:18.402-05:00">DRAFT</status_change>
            <status_change date="2010-02-15T04:00:12.698-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:16.370-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6359 - corrected regex (symbol '\' not needed before symbol '_')" date="2013-09-06T13:39:00.864-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-06T13:43:17.724-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:05:40.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.0 is installed" definition_ref="oval:org.mitre.oval:def:8282"/>
          <criterion comment="MySQL Server 5.0 version is less than 5.0.88" test_ref="oval:org.mitre.oval:tst:20192"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
          <criterion comment="MySQL Server 5.1 version is less than 5.1.41" test_ref="oval:org.mitre.oval:tst:20859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8503" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.5 and SeaMonkey Multiple Remote Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3980"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:54.147-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:29.553-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:11.857-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:16.553-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:15.277-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:32.064-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:22.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8503 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:24.238-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.016-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6323 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:02.991-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:02.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8503 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:28.781-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:24.005-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:17.384-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:38.669-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8500" version="3" class="vulnerability">
      <metadata>
        <title>MySQL 5.0 and 5.1 SELECT Statement DOS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 5.0</product>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4019"/>
        <description>mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-22T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-27T13:49:18.646-05:00">DRAFT</status_change>
            <status_change date="2010-02-15T04:00:11.539-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:15.716-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6359 - corrected regex (symbol '\' not needed before symbol '_')" date="2013-09-06T13:39:00.864-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-06T13:43:17.389-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:05:40.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.0 is installed" definition_ref="oval:org.mitre.oval:def:8282"/>
          <criterion comment="MySQL Server 5.0 version is less than 5.0.88" test_ref="oval:org.mitre.oval:tst:20192"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
          <criterion comment="MySQL Server 5.1 version is less than 5.1.41" test_ref="oval:org.mitre.oval:tst:20859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8491" version="10" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0245)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0245"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:41.311-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:17.250-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:28.410-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:02.660-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:50.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:45.701-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:05.463-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.446-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.446-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:19.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8491 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.487-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:36.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8490" version="10" class="vulnerability">
      <metadata>
        <title>Wireshark Dissector LWRES Multiple Buffer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0304"/>
        <description>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-04T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-08T15:16:11.352-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:31.499-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:16.437-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8490 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:21.364-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:20.938-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6649 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:59.644-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:04.452-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:26.989-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:21.387-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8490 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:42.247-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:18.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed on the system is 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5" test_ref="oval:org.mitre.oval:tst:20124"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8489" version="13" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 'window.opener' Property Chrome Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3986"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:52.417-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:29.236-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:11.191-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:03.919-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:14.830-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:38.559-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:22.552-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5740 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:50.190-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:01.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8489 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:40.297-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:23.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.743-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:38.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8487" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey Multiple Remote Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3979"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:54.392-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:28.833-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:10.771-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:02.892-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:14.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:38.157-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:22.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8487 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:09.020-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:53.901-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5740 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:50.083-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:01.764-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8487 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:26.837-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:23.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.595-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:38.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8485" version="20" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and SeaMonkey Browser Engine Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0159"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-04T12:37:22.956-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:18.460-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:30.634-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:01.600-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:13.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:37.284-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:21.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8485 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:18.754-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:53.784-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6715 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:01.967-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:01.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:45.148-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8485 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:8485 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:29.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:43.184-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8485 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:23.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:41.544-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:38.148-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.2" test_ref="oval:org.mitre.oval:tst:114991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8480" version="13" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Sea Monkey Content Injection Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:52.678-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:28.458-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:10.443-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:07.756-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:13.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:46.222-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:21.231-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5740 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:49.977-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:01.501-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8480 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:34.949-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:23.341-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:25.026-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:37.962-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8479" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0261"/>
        <description>Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:04.198-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:30.316-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:15.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:09.779-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:55.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:29.958-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:29.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20930"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6529.5000" test_ref="oval:org.mitre.oval:tst:21005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8472" version="12" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 'TraceRecorder::traverseScopeChain()' Remote Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0165"/>
        <description>The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:00.485-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:28.899-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:14.191-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:00.679-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:13.198-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:56.822-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:01.222-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8472 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:36.683-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:23.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:16.624-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:37.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8465" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey Web Worker Array Handling Heap Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0160"/>
        <description>The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-04T12:37:21.506-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:17.522-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:28.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:56.470-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:12.690-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:41.842-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:20.745-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8465 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:09.779-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:53.665-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6715 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:01.867-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:01.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8465 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:36.513-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:22.957-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:15.975-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:37.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8464" version="12" class="vulnerability">
      <metadata>
        <title>URL Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0027"/>
        <description>The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:39.590-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:19:00.314-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Added checks for Schlwapi.dll" date="2010-02-10T13:06:00.077-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:26.899-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:16.416-04:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.486-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:48.965-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:47.784-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:04.384-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.822-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.822-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:18.191-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.005-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:27.040-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8464 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:28.718-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:36.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Shlwapi.dll version is less than 5.0.3900.7349" test_ref="oval:org.mitre.oval:tst:20440"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Shlwapi.dll version is less than 6.0.2900.3653" test_ref="oval:org.mitre.oval:tst:20970"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Shlwapi.dll version is less than 6.0.2900.5912" test_ref="oval:org.mitre.oval:tst:20936"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="Shlwapi.dll version is less than 6.0.3790.4603" test_ref="oval:org.mitre.oval:tst:20977"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8455" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Download Manager Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3958"/>
        <description>Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:12.096-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:38.248-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:10.670-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.968-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:36.669-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:42.469-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:52.695-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:30.275-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:10.953-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:03.920-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:06.563-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:27.505-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:30.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8439" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_isapi' Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0425" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0425"/>
        <description>modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:14.092-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:48.616-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:30.076-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:03.359-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:52.351-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.353-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:29.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.15" test_ref="oval:org.mitre.oval:tst:21012"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8438" version="3" class="vulnerability">
      <metadata>
        <title>SMB Pathname Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0020"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:54.857-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:25.104-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:14.869-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.915-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.915-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:17.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8434" version="13" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.5 JavaScript Engine Multiple Remote Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3982"/>
        <description>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:53.550-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:28.148-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:10.118-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:31.352-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:12.312-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:25.485-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:20.336-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6323 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:02.655-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:00.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8434 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:33.444-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:22.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:13.282-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:37.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8431" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Cached XUL Stylesheets Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0169"/>
        <description>The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:01.073-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:25.935-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:11.639-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:31.952-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:11.820-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:26.920-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:19.822-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:57.411-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:00.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:05.987-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8431 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:8431 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:29.371-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:01.571-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8431 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:22.469-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:54.191-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:37.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.3" test_ref="oval:org.mitre.oval:tst:100795"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.2" test_ref="oval:org.mitre.oval:tst:114991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8424" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Data Analyzer ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0252"/>
        <description>The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:10.997-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:23.593-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:13.627-04:00">ACCEPTED</status_change>
            <modified comment="Added additional criteria for Active X control detection." date="2010-06-14T10:40:00.826-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-06-14T10:46:39.917-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:06.002-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.603-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.603-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:16.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:53.249-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:33.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E0ECA9C3-D669-4EF4-8231-00724ED9288F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:20990"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E0ECA9C3-D669-4EF4-8231-00724ED9288F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:21016"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{14FD1463-1F3F-4357-9C03-2080B442F503}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27468"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{14FD1463-1F3F-4357-9C03-2080B442F503}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27497"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CB13DB-20AB-43C5-B283-977C58FB5754}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27250"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CB13DB-20AB-43C5-B283-977C58FB5754}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8410" version="3" class="vulnerability">
      <metadata>
        <title>PowerPoint File Path Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office PowerPoint 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0029"/>
        <description>Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:39.977-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:23.298-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:13.310-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:21080 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:26.495-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:43.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="PowerPoint 2002">
        <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
        <criterion comment="Powerpnt.exe is less than version 10.0.6858.0" test_ref="oval:org.mitre.oval:tst:21080"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8407" version="14" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel XLSX File Parsing Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
          <product>Microsoft Office SharePoint Server 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0263"/>
        <reference source="Microsoft" ref_id="MS10-017" ref_url="http://technet.microsoft.com/ru-ru/security/bulletin/ms10-017"/>
        <description>Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, which allows remote attackers to execute arbitrary code via a crafted document that triggers access to uninitialized memory locations, aka "Microsoft Office Excel XLSX File Parsing Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:05.468-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:23.087-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:09.135-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12092 - Corrected the comment for the obj:12092" date="2011-08-15T08:21:00.518-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-08-15T08:22:34.011-04:00">INTERIM</status_change>
            <status_change date="2011-09-05T04:00:19.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:10.203-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:53.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:53.348-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:39.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8407 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-30T10:26:28.638-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:29.041-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8407 - Microsoft reference was added and extend_definitions were combined in criteria with OR operator" date="2014-07-31T12:19:00.882-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-31T12:20:20.335-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:35.572-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <criteria operator="OR" comment="Microsoft Excel 2007 SP1/SP2">
            <extend_definition comment="Microsoft Excel 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24830"/>
            <extend_definition comment="Microsoft Excel 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15538"/>
          </criteria>
          <criterion comment="Excel.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20930"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <criteria operator="OR" comment="Microsoft Excel Viewer 2007 SP1/SP2">
            <extend_definition comment="Microsoft Excel Viewer 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24660"/>
            <extend_definition comment="Microsoft Excel Viewer 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:24760"/>
          </criteria>
          <criterion comment="Xlview.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20847"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR" comment="Microsoft Office Compatibility Pack SP1/SP2 /Microsoft Office 2007 SP2">
            <extend_definition comment="Microsoft Office Compatibility Pack SP2 is installed" definition_ref="oval:org.mitre.oval:def:15640"/>
            <extend_definition comment="Microsoft Office Compatibility Pack SP1 is installed" definition_ref="oval:org.mitre.oval:def:23850"/>
            <extend_definition comment="Microsoft Office 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15607"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6529.5000" test_ref="oval:org.mitre.oval:tst:21005"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Office SharePoint Server 2007">
          <criteria operator="OR" comment="Microsoft Office SharePoint Server 2007 SP1/SP2">
            <extend_definition comment="Microsoft Office SharePoint Server 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24769"/>
            <extend_definition comment="Microsoft Office SharePoint Server 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15502"/>
          </criteria>
          <criterion comment="Microsoft Office Excel Services are installed" test_ref="oval:org.mitre.oval:tst:21101"/>
          <criterion comment="xlsrv.dll version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:21116"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24830" version="4" class="inventory">
      <metadata>
        <title>Microsoft Excel 2007 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Excel 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:excel:2007:sp1"/>
        <description>Microsoft Excel 2007 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-20T13:00:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-05-30T10:26:15.763-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23201 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-16T04:00:16.488-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:22.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Office 2007 products is greater than or equal to 12.0.6214.1000" test_ref="oval:org.mitre.oval:tst:114657"/>
        <criterion comment="Check if the version of Office 2007 products is less than 12.0.6425.1000" test_ref="oval:org.mitre.oval:tst:114188"/>
        <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24769" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2007 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint:2007:sp1"/>
        <description>SharePoint Server 2007 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-08T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-05-30T10:26:16.037-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:16.118-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:19.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
        <criterion comment="Check if SharePoint Server 2007 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114612"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24660" version="4" class="inventory">
      <metadata>
        <title>Microsoft Excel Viewer 2007 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Excel Viewer 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:excel_viewer:2007:sp1"/>
        <description>Microsoft Excel Viewer 2007 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-20T13:00:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-05-30T10:26:15.243-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23201 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-16T04:00:13.421-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:18.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
        <criterion comment="Check if the version of Office 2007 products is greater than or equal to 12.0.6211.1000 and is less than 12.0.6425.1000" test_ref="oval:org.mitre.oval:tst:114411"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23850" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Compatibility Pack SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_compatibility_pack:sp1"/>
        <description>The application Microsoft Office Compatibility Pack SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-08T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-05-20T12:43:50.440-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:20.899-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:56.541-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="AND" comment="Check for Microsoft Office Compatibility Pack SP2">
          <criterion comment="Check if ProductVersion of Microsoft Office Compatibility Pack is greater than or equal to 12.0.6211.1000" test_ref="oval:org.mitre.oval:tst:114109"/>
          <criterion comment="Check if ProductVersion of Microsoft Office Compatibility Pack is less than 12.0.6425.1000" test_ref="oval:org.mitre.oval:tst:113990"/>
        </criteria>
        <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8399" version="1" class="vulnerability">
      <metadata>
        <title>MSO.DLL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0243"/>
        <description>Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:36.382-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:22.458-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:12.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
        <criterion comment="Mso.dll version is less than 10.0.6858.0" test_ref="oval:org.mitre.oval:tst:20723"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8394" version="7" class="vulnerability">
      <metadata>
        <title>Apache APR and APR-util Multiple Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"/>
        <description>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:15.475-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:48.324-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:29.721-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:03.659-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:51.594-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.442-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:29.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.13" test_ref="oval:org.mitre.oval:tst:21055"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8393" version="13" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0187"/>
        <description>Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-02-15T10:50:44.534-05:00">DRAFT</status_change>
            <status_change date="2010-03-08T04:00:15.139-05:00">INTERIM</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:6598" date="2010-03-22T10:44:00.040-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:21.475-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:41.991-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:33.077-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:57.961-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:48.746-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:08.574-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:57.899-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:21.102-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:21062 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:37.059-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8393 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:41:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:43:30.704-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:08.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than or equal 1.5.3.9120" test_ref="oval:org.mitre.oval:tst:21062"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8392" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel Double Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0233"/>
        <description>Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:36.420-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:21.474-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:11.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7364" test_ref="oval:org.mitre.oval:tst:20965"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3654" test_ref="oval:org.mitre.oval:tst:20861"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5913" test_ref="oval:org.mitre.oval:tst:20875"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4637" test_ref="oval:org.mitre.oval:tst:21038"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.16973" test_ref="oval:org.mitre.oval:tst:21001"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21175" test_ref="oval:org.mitre.oval:tst:21086"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18377" test_ref="oval:org.mitre.oval:tst:21094"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22577" test_ref="oval:org.mitre.oval:tst:20290"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18160" test_ref="oval:org.mitre.oval:tst:20720"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22283" test_ref="oval:org.mitre.oval:tst:20937"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - GDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:20790"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - LDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:20976"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8379" version="13" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Sea Monkey Insecure Protocol Location Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3984"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:52.942-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:27.799-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:09.464-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:39.451-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:11.410-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:45.346-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:19.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5740 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:49.765-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:02:00.122-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8379 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:38.184-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:22.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.495-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:36.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8378" version="10" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0246)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0246"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0245.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:41.857-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:13.463-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:20.715-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.603-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:47.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:44.972-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:03.549-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:52.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:52.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:15.264-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8378 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.232-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:35.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8371" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy_balancer' Cross-Site Request Forgery (CSRF) Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6420"/>
        <description>Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:17.150-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:47.264-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:29.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:03.959-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:50.849-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.532-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:29.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than 2.2.9" test_ref="oval:org.mitre.oval:tst:20474"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8355" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey XSS Vulnerability due to window.dialogArguments being readable cross-domain</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3988"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-04T12:37:21.253-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:11.189-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:19.999-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:20.607-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:10.950-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:32.865-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:18.758-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8355 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:36.775-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:53.548-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6715 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:01.761-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:59.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8355 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:37.268-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:21.982-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:22.759-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:36.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8344" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel Exception Handler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0232"/>
        <description>The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:37.616-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:19.970-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:10.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7364" test_ref="oval:org.mitre.oval:tst:20965"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3654" test_ref="oval:org.mitre.oval:tst:20861"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5913" test_ref="oval:org.mitre.oval:tst:20875"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4637" test_ref="oval:org.mitre.oval:tst:21038"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86 - GDR">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.16973" test_ref="oval:org.mitre.oval:tst:21001"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86 - LDR">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21175" test_ref="oval:org.mitre.oval:tst:21086"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86, Server 2008 32bit - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18377" test_ref="oval:org.mitre.oval:tst:21094"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86, Server 2008 32bit - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22577" test_ref="oval:org.mitre.oval:tst:20290"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86, Server 2008 SP2 32bit - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18160" test_ref="oval:org.mitre.oval:tst:20720"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86, Server 2008 SP2 32bit - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22283" test_ref="oval:org.mitre.oval:tst:20937"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - GDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:20790"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - LDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:20976"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8327" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Remote Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3956" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3956"/>
        <description>The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:11.338-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:37.779-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:10.237-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:10.393-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:36.180-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:52.608-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:50.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:39.077-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:10.427-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:12.414-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:05.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:46.183-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:29.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8324" version="5" class="vulnerability">
      <metadata>
        <title>Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018"/>
        <description>Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-12T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:56.446-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:36.628-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:09.040-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:58.415-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:58.415-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:13.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4217 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:21.123-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.0.2195.7348 or T2embed.dll &lt; 5.0.2195.7348">
            <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7348" test_ref="oval:org.mitre.oval:tst:20934"/>
            <criterion comment="the version of T2embed.dll is less than 5.0.2195.7348" test_ref="oval:org.mitre.oval:tst:20771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.3634 or T2embed.dll &lt; 5.1.2600.3634">
            <criterion comment="the version of Fontsub.dll is less than 5.1.2600.3634" test_ref="oval:org.mitre.oval:tst:20493"/>
            <criterion comment="the version of T2embed.dll is less than 5.1.2600.3634" test_ref="oval:org.mitre.oval:tst:20574"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.5888 or T2embed.dll &lt; 5.1.2600.5888">
            <criterion comment="the version of Fontsub.dll is less than 5.1.2600.5888" test_ref="oval:org.mitre.oval:tst:20330"/>
            <criterion comment="the version of T2embed.dll is less than 5.1.2600.5888" test_ref="oval:org.mitre.oval:tst:20465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.2.3790.4603 or T2embed.dll &lt; 5.2.3790.4603">
            <criterion comment="the version of Fontsub.dll is less than 5.2.3790.4603" test_ref="oval:org.mitre.oval:tst:20803"/>
            <criterion comment="the version of T2embed.dll is less than 5.2.3790.4603" test_ref="oval:org.mitre.oval:tst:20441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6000.16939 or T2embed.dll &lt;6.0.6000.16939">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.16939" test_ref="oval:org.mitre.oval:tst:20960"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6000.16939" test_ref="oval:org.mitre.oval:tst:20880"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6000.16000 or T2embed.dll >= 6.0.6000.16000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10227"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9969"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6000.21142 or T2embed.dll &lt;6.0.6000.21142">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.21142" test_ref="oval:org.mitre.oval:tst:20834"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6000.21142" test_ref="oval:org.mitre.oval:tst:20901"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6000.20000 or T2embed.dll >= 6.0.6000.20000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10116"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10120"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6001.18344 or T2embed.dll &lt;6.0.6001.18344">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.18344" test_ref="oval:org.mitre.oval:tst:20514"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.18344" test_ref="oval:org.mitre.oval:tst:20947"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6001.18000 or T2embed.dll >= 6.0.6001.18000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10215"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6001.22544 or T2embed.dll &lt;6.0.6001.22544">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.22544" test_ref="oval:org.mitre.oval:tst:20693"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.22544" test_ref="oval:org.mitre.oval:tst:20548"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6001.22000 or T2embed.dll >= 6.0.6001.22000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9819"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6002.18124 or T2embed.dll &lt;6.0.6002.18124">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.18124" test_ref="oval:org.mitre.oval:tst:20931"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.18124" test_ref="oval:org.mitre.oval:tst:20968"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6002.18000 or T2embed.dll >= 6.0.6002.18000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20873"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20791"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6002.22247 or T2embed.dll &lt;6.0.6002.22247">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.22247" test_ref="oval:org.mitre.oval:tst:20307"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.22247" test_ref="oval:org.mitre.oval:tst:20076"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6002.22000 or T2embed.dll >= 6.0.6002.22000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10029"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is less than 6.1.7600.16444" test_ref="oval:org.mitre.oval:tst:20573"/>
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.16444" test_ref="oval:org.mitre.oval:tst:20972"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20730"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20874"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is less than 6.1.7600.20553" test_ref="oval:org.mitre.oval:tst:20953"/>
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.20553" test_ref="oval:org.mitre.oval:tst:20599"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20857"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20099"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8317" version="11" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox jstracer.cpp Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1203"/>
        <description>The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-07T10:30:56">
              <contributor organization="SecPod Technologies">Nikita MR</contributor>
            </submitted>
            <status_change date="2010-07-07T16:18:27.310-04:00">DRAFT</status_change>
            <status_change date="2010-07-26T04:00:03.642-04:00">INTERIM</status_change>
            <status_change date="2010-08-16T04:10:50.140-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:48.293-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:10.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8317 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:30.909-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:21.828-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:15.613-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:36.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.4" test_ref="oval:org.mitre.oval:tst:121139"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8314" version="3" class="vulnerability">
      <metadata>
        <title>SMB Null Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0022"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:55.645-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:19.120-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:09.453-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:12.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8311" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4002"/>
        <description>Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-20T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:04.860-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:06.945-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:18.767-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:05.455-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:37.020-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.6.606" test_ref="oval:org.mitre.oval:tst:21023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8303" version="3" class="vulnerability">
      <metadata>
        <title>PowerPoint OEPlaceholderAtom Use After Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office PowerPoint 2002</product>
          <product>Microsoft Office PowerPoint 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0032"/>
        <description>Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:39.746-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:18.078-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:08.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:21080 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:27.189-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:42.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="PowerPoint 2002">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="Powerpnt.exe is less than version 10.0.6858.0" test_ref="oval:org.mitre.oval:tst:21080"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="Powerpnt.exe is less than version 11.0.8318.0" test_ref="oval:org.mitre.oval:tst:20855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8302" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0490)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0490" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0490"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:24.602-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:46.225-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:28.200-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:50.754-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:02.260-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.837-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:11.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:05.018-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:26.293-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8302 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:33.278-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:34.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8298" version="6" class="vulnerability">
      <metadata>
        <title>SMB Client Race Condition Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0017"/>
        <description>Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:59.309-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:17.371-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:07.879-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:49.837-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:49.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:11.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:14.307-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:25.907-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.16971" test_ref="oval:org.mitre.oval:tst:20528"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21173" test_ref="oval:org.mitre.oval:tst:20673"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18375" test_ref="oval:org.mitre.oval:tst:20973"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22575" test_ref="oval:org.mitre.oval:tst:21096"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18158" test_ref="oval:org.mitre.oval:tst:20724"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22281" test_ref="oval:org.mitre.oval:tst:21061"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16499" test_ref="oval:org.mitre.oval:tst:21051"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20612" test_ref="oval:org.mitre.oval:tst:20955"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8292" version="9" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Memory Consumption DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0220" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0220"/>
        <description>The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-08T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-12T16:25:58.913-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:36.329-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:08.662-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:02.603-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:10.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8292 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:38.340-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:21.700-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.679-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:36.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Mozilla Firefox Mainline version is before 3.0.17" test_ref="oval:org.mitre.oval:tst:120764"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.7" test_ref="oval:org.mitre.oval:tst:120975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8281" version="12" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Asynchronous HTTP Authorization Prompt Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0172" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0172"/>
        <description>toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:00.299-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:16.638-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:03.175-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:06.483-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:09.811-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:56.898-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:59.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8281 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:36.958-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:21.535-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.940-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:36.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8268" version="3" class="vulnerability">
      <metadata>
        <title>Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office PowerPoint 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0034"/>
        <description>Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:40.428-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:16.417-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:07.159-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:850 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:43.570-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:41.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="PowerPoint 2003">
        <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
        <criterion comment="Powerpnt.exe is less than version 11.0.8318.0" test_ref="oval:org.mitre.oval:tst:20855"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8267" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0248)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0248"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:42.498-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:28:00.020-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:07.637-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:13.167-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.246-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:44.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:51.808-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:01.011-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:55.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:55.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:09.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:04.076-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:25.552-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8267 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:29.620-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:33.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8261" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy_ajp' Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1191"/>
        <description>mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:16.514-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:44.639-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:27.798-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:02.367-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:49.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.003-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:28.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is equal to 2.2.11" test_ref="oval:org.mitre.oval:tst:20885"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8255" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat JpxDecode Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3955" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3955"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:10.241-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:35.861-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:08.212-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.119-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:35.573-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:39.380-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:48.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:44.492-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:09.829-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:22.621-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:05.187-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:20.886-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:29.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8248" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1206"/>
        <description>The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-07T10:30:25">
              <contributor organization="SecPod Technologies">Nikita MR</contributor>
            </submitted>
            <status_change date="2010-07-07T16:18:24.545-04:00">DRAFT</status_change>
            <modified comment="Added tests for Mozilla Seamonkey" date="2010-07-22T10:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-09T04:00:16.804-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:15.860-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:32.171-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:09.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8248 - Mods to address seamonkey prior to 2.0" date="2013-09-04T14:13:00.131-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-04T14:17:42.991-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11851 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-10-07T04:12:18.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8248 - Corrected test for SeaMonkey registry key" date="2013-11-07T08:05:00.580-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-07T08:10:36.606-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:30.462-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8248 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:50.493-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:59.021-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8248 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:26.167-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:21.349-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.172-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:35.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.11" test_ref="oval:org.mitre.oval:tst:120630"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.7" test_ref="oval:org.mitre.oval:tst:121011"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.6" test_ref="oval:org.mitre.oval:tst:100360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8242" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat U3D Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3953" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3953"/>
        <description>The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:10.604-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:35.439-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:07.698-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.585-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:35.086-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:45.414-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:48.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:50.166-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:09.052-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:27.799-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:04.487-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:31.745-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:28.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8240" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey NTLM Credential Reflection Authentication Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3983"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:53.256-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:27.493-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:07.236-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:34.919-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:08.923-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:41.436-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:17.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8240 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:39.204-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:53.209-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5740 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:49.870-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:58.892-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8240 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:31.097-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:21.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.408-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:35.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8186" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0244)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0244"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:40.415-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:27:00.242-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:06.196-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:11.792-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.760-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:43.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:43.866-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:59.772-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.306-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.306-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:08.761-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:07.178-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:25.188-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8186 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.907-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:32.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8156" version="3" class="vulnerability">
      <metadata>
        <title>MySQL 5.1 Privilege Bypass with DATA/INDEX DIRECTORY</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4030"/>
        <description>MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-22T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-27T13:49:18.121-05:00">DRAFT</status_change>
            <status_change date="2010-02-15T04:00:05.803-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:11.412-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6693 - corrected regex (symbol '\' not needed before symbol '_')" date="2013-09-06T13:39:00.864-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-06T13:43:18.489-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:05:39.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
        <criterion comment="MySQL Server 5.1 version is less than 5.1.41" test_ref="oval:org.mitre.oval:tst:20859"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8087" version="8" class="vulnerability">
      <metadata>
        <title>Apache mod_proxy_ftp Module Insufficient Input Validation Denial Of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3094"/>
        <description>The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:14.893-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12000 - Added beginning anchor to the key pattern match" date="2010-05-13T15:36:00.402-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:43.186-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:27.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12000 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:47.201-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:47.631-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.231-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:28.723-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Apache HTTP Server 2.0.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8605"/>
          <criterion comment="The version of libhttpd.dll is less than 2.0.64" test_ref="oval:org.mitre.oval:tst:21065"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
          <criterion comment="The version of libhttpd.dll is less than 2.2.14" test_ref="oval:org.mitre.oval:tst:21129"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8081" version="3" class="vulnerability">
      <metadata>
        <title>PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office PowerPoint 2002</product>
          <product>Microsoft Office PowerPoint 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0031"/>
        <description>Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:39.499-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:15.784-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:06.746-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:21080 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:26.189-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:41.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="PowerPoint 2002">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="Powerpnt.exe is less than version 10.0.6858.0" test_ref="oval:org.mitre.oval:tst:21080"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="Powerpnt.exe is less than version 11.0.8318.0" test_ref="oval:org.mitre.oval:tst:20855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8064" version="3" class="vulnerability">
      <metadata>
        <title>DirectShow Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0250"/>
        <description>Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:11.294-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:14.814-05:00">INTERIM</status_change>
            <modified comment="Switched the version tests for Quartz.dll on Windows 2000; with DirectX 9.0x should be 6.5.1.913, without DirectX 9.0x should be 6.1.9.738" date="2010-03-12T14:20:00.051-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:11.304-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:07.764-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / AVI filter">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Avifil32.dll is less than 5.0.2195.7359" test_ref="oval:org.mitre.oval:tst:21095"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / Quartz">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.738" test_ref="oval:org.mitre.oval:tst:21059"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / Quartz in DirectX 9.0">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.913" test_ref="oval:org.mitre.oval:tst:20854"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2 / AVI filter">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.3649" test_ref="oval:org.mitre.oval:tst:20939"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2 / Quartz">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3649" test_ref="oval:org.mitre.oval:tst:21048"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3 / AVI filter">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.5908" test_ref="oval:org.mitre.oval:tst:20757"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3 / Quartz">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5908" test_ref="oval:org.mitre.oval:tst:20736"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2 / AVI filter">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 5.2.3790.4625" test_ref="oval:org.mitre.oval:tst:21066"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2 / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4625" test_ref="oval:org.mitre.oval:tst:21092"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.16986" test_ref="oval:org.mitre.oval:tst:20777"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.16000" test_ref="oval:org.mitre.oval:tst:20862"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.21188" test_ref="oval:org.mitre.oval:tst:21082"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.20000" test_ref="oval:org.mitre.oval:tst:21068"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.18389" test_ref="oval:org.mitre.oval:tst:20105"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.18000" test_ref="oval:org.mitre.oval:tst:21070"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.22590" test_ref="oval:org.mitre.oval:tst:20946"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.22000" test_ref="oval:org.mitre.oval:tst:20940"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6002.18158" test_ref="oval:org.mitre.oval:tst:20526"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6002.18000" test_ref="oval:org.mitre.oval:tst:20145"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6002.22295" test_ref="oval:org.mitre.oval:tst:20952"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6002.22000" test_ref="oval:org.mitre.oval:tst:20775"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.7600.16490" test_ref="oval:org.mitre.oval:tst:20879"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.6.7600.16000" test_ref="oval:org.mitre.oval:tst:20619"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.7600.20600" test_ref="oval:org.mitre.oval:tst:20804"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.6.7600.20000" test_ref="oval:org.mitre.oval:tst:20613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8050" version="3" class="vulnerability">
      <metadata>
        <title>PowerPoint LinkedSlideAtom Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office PowerPoint 2002</product>
          <product>Microsoft Office PowerPoint 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0030"/>
        <description>Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:39.224-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:14.451-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:06.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:21080 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:26.778-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:40.292-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="PowerPoint 2002">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="Powerpnt.exe is less than version 10.0.6858.0" test_ref="oval:org.mitre.oval:tst:21080"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="Powerpnt.exe is less than version 11.0.8318.0" test_ref="oval:org.mitre.oval:tst:20855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8009" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey 'liboggplay' Media Library Remote Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3388"/>
        <description>liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:54.891-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:27.180-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:05.477-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:53.633-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:08.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:40.263-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:17.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8009 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:05.721-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:53.097-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6323 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:02.568-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:58.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8009 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:32.598-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:20.805-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:21.671-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:35.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7975" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Null Pointer Dereference Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3957" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3957"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-13T08:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:11.680-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:34.482-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:06.868-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.220-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:34.505-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:40.900-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:46.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:25.361-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:08.432-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:00.490-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:03.623-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:22.940-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:27.489-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7969" version="12" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox WOFF Processing Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1028"/>
        <description>Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T09:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:35.422-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:09.335-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:56.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:47.787-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:08.121-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:57.004-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:58.262-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7969 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:35.567-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:20.604-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.703-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:35.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7967" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey Theora Video Library Remote Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3389"/>
        <description>Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:54.644-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:26.817-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:05.148-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:50.375-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:07.667-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:29.087-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:16.942-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7967 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:28.883-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.967-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6323 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:23:03.094-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:58.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7967 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:28.344-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:20.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.839-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:35.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7958" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey GeckoActiveXObject Exception Message COM Object Enumeration Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3987"/>
        <description>The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-08T15:51:52.133-05:00">DRAFT</status_change>
            <status_change date="2010-01-25T04:00:26.497-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:04.766-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:08.435-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:07.207-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:47.568-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:16.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7958 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:41.612-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.848-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5740 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:50.279-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:57.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7958 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:29.281-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:20.232-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:25.114-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:35.078-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.16" test_ref="oval:org.mitre.oval:tst:120907"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.5" test_ref="oval:org.mitre.oval:tst:121048"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.1" test_ref="oval:org.mitre.oval:tst:100118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7923" version="4" class="vulnerability">
      <metadata>
        <title>Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0010"/>
        <description>Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-04T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:18.350-05:00">DRAFT</status_change>
            <modified comment="Added anchor to regular expression" date="2010-03-22T10:45:00.568-04:00">
              <contributor organization="The MITRE Corporation">Matt Hansbury</contributor>
            </modified>
            <modified comment="Added anchor to regular expression" date="2010-03-22T10:46:00.314-04:00">
              <contributor organization="The MITRE Corporation">Matt Hansbury</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:08.770-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:55.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:51.220-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:15.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Windows 64 bit platform">
          <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        </criteria>
        <extend_definition comment="Apache HTTP Server 1.3.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8565"/>
        <criterion comment="The version of Apache HTTP Server is less than 1.3.42" test_ref="oval:org.mitre.oval:tst:21143"/>
        <criterion comment="ApacheCore.dll exists" test_ref="oval:org.mitre.oval:tst:20505"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8565" version="4" class="inventory">
      <metadata>
        <title>Apache HTTP Server 1.3.x is installed on the system</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:apache:http_server:1.3"/>
        <description>Apache HTTP Server 1.3.x is installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-04T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:13.187-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:39.466-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:24.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1436 - vulnerabilities for VMware and inventories for VMware Workstation, VMware View and VMware Player." date="2013-06-21T12:00:00.019-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-21T12:13:28.966-04:00">INTERIM</status_change>
            <status_change date="2013-07-08T04:03:01.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check for the Apache HTTP Server 1.3 installation." test_ref="oval:org.mitre.oval:tst:20454"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7888" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0264" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0264"/>
        <description>Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:04.658-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:07.280-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:54.376-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:02.183-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:38.808-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Vulnerable Excel 2002">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6860.0" test_ref="oval:org.mitre.oval:tst:20982"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7862" version="9" class="vulnerability">
      <metadata>
        <title>Microsoft Office Excel MDXTUPLE Record Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0260"/>
        <description>Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into several records," aka "Microsoft Office Excel MDXTUPLE Record Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-10T11:31:03.826-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:06.678-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:53.733-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:01.761-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:52.903-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:46.989-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:38.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:13.856-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:28.858-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20930"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20847"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6529.5000" test_ref="oval:org.mitre.oval:tst:21005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7751" version="3" class="vulnerability">
      <metadata>
        <title>SMB NTLM Authentication Lack of Entropy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0231"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:56.561-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:12.404-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:05.057-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:06.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7743" version="21" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/SeaMonkey Multiple Cross Domain Scripting Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0171" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0171"/>
        <description>Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-25T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:01.359-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:01.454-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:48.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:58.402-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:06.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:44.457-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:15.951-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7743 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:15.991-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.709-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6770 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:57.510-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:57.125-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:37.296-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7743 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7743 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:28.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:35.128-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7743 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:20.033-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:32.014-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:34.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.18" test_ref="oval:org.mitre.oval:tst:120795"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.8" test_ref="oval:org.mitre.oval:tst:121022"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x to 3.6.1" test_ref="oval:org.mitre.oval:tst:121072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.2" test_ref="oval:org.mitre.oval:tst:114991"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7722" version="10" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2010-0492)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0492"/>
        <description>Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:26.174-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:42.516-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:26.679-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:50.106-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:59.007-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.228-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.228-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:05.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7722 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:32.675-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.984-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7716" version="8" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2939"/>
        <description>Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:16.797-05:00">DRAFT</status_change>
            <modified comment="Edited obj:12000 - Added beginning anchor to the key pattern match" date="2010-05-13T15:36:00.402-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited obj:12088 - Added beginning anchor to the key pattern match" date="2010-05-13T15:41:00.976-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:42.178-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:26.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12000 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:47.861-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:46.027-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:00.627-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:28.254-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Apache HTTP Server 2.0.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8605"/>
          <criterion comment="The version of libhttpd.dll is less than 2.0.64" test_ref="oval:org.mitre.oval:tst:21065"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
          <criterion comment="The version of libhttpd.dll is less than 2.2.10" test_ref="oval:org.mitre.oval:tst:20971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7715" version="10" class="vulnerability">
      <metadata>
        <title>XSS Filter Script Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4074"/>
        <description>The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:38.969-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:01:05.623-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:11.481-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.456-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:41.397-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:52.945-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:58.244-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.384-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.384-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:04.707-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7715 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:33.625-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7711" version="3" class="vulnerability">
      <metadata>
        <title>PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office PowerPoint 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0033"/>
        <description>Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:40.230-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:11.178-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:04.716-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:850 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:40.989-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:38.243-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="PowerPoint 2003">
        <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
        <criterion comment="Powerpnt.exe is less than version 11.0.8318.0" test_ref="oval:org.mitre.oval:tst:20855"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7709" version="9" class="vulnerability">
      <metadata>
        <title>libpng buffer overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>MSN Messenger 4.7</product>
          <product>MSN Messenger 6.1</product>
          <product>MSN Messenger 6.2</product>
          <product>Adobe Acrobat Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-15T14:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-03-02T12:13:45.370-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:03.375-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:58.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:40.791-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:51.447-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:04.904-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:28.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:405 - Adobe Acrobat Reader 6 inventory" date="2014-09-17T10:34:00.391-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:36:11.001-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:34.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7709 - corrected platform info" date="2015-04-17T09:36:00.491-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:39:11.303-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:21.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Messenger 5.0">
          <criteria operator="OR" comment="Microsoft Windows 2000 SP4, Windows Server 2003 (x86) Gold, Windows Server 2003 SP1 (x86), Windows XP Professional x64 Edition SP1, Windows XP SP1 (32-bit), Windows XP (x86) SP2">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          </criteria>
          <criterion comment="the version of msmsgs.exe is greater than or equal to 5.0.0.0" test_ref="oval:org.mitre.oval:tst:20625"/>
          <criterion comment="the version of msmsgs.exe is less than 5.1.0.639" test_ref="oval:org.mitre.oval:tst:563"/>
        </criteria>
        <criteria operator="AND" comment="Windows Messenger 4.7 on Windows XP SP1 32-bit">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <extend_definition comment="MSN Messenger 4.7 is installed" definition_ref="oval:org.mitre.oval:def:6101"/>
          <criterion comment="the version of msmsgs.exe is less than 4.7.0.2010" test_ref="oval:org.mitre.oval:tst:20951"/>
        </criteria>
        <criteria operator="AND" comment="Windows Messenger 4.7 on Windows XP SP2 (x86)">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="MSN Messenger 4.7 is installed" definition_ref="oval:org.mitre.oval:def:6101"/>
          <criterion comment="the version of msmsgs.exe is less than 4.7.0.3001" test_ref="oval:org.mitre.oval:tst:21102"/>
        </criteria>
        <criteria operator="AND" comment="MSN Messenger 6.1/6.2">
          <criteria operator="OR" comment="MSN Messenger 6.1, MSN Messenger 6.2">
            <extend_definition comment="MSN Messenger 6.1 is installed" definition_ref="oval:org.mitre.oval:def:8701"/>
            <extend_definition comment="MSN Messenger 6.2 is installed" definition_ref="oval:org.mitre.oval:def:2187"/>
          </criteria>
          <criterion negate="true" comment="MSN Messenger 6.2.0205 or later is installed" test_ref="oval:org.mitre.oval:tst:2519"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat Reader 6">
          <criterion comment="the software Adobe Acrobat Reader 6, major version 6 is installed" test_ref="oval:org.mitre.oval:tst:471"/>
          <criterion comment="the software Adobe Acrobat Reader 6, minor version less than 3 is installed" test_ref="oval:org.mitre.oval:tst:470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8701" version="7" class="inventory">
      <metadata>
        <title>MSN Messenger 6.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger 6.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:6.1"/>
        <description>MSN Messenger 6.1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-15T14:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-03-02T12:13:44.787-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:21.643-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:01:51.010-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8701 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:43.955-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:27.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1436 - vulnerabilities for VMware and inventories for VMware Workstation, VMware View and VMware Player." date="2013-06-21T12:00:00.019-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-21T12:13:31.699-04:00">INTERIM</status_change>
            <status_change date="2013-07-08T04:03:02.219-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8701 - Modified MSN Messenger inventories: Fixed product version info" date="2015-04-10T10:01:00.091-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:03:13.672-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:28.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MSN Messenger 6.1 is installed" test_ref="oval:org.mitre.oval:tst:20924"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:720" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows XP Professional x64 Edition SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp1:x64"/>
        <description>A version of Microsoft Windows XP Professional x64 Edition Service Pack 1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.909-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:27.909-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.527-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:28:52.548-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:23.716-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:01:06.706-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:01:10.364-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:18.431-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:06.883-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:10.152-05:00">INTERIM</status_change>
            <modified comment=" Changed the tests for SP1 and windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:55.866-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:35.612-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:24.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:48.110-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:11.990-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6101" version="6" class="inventory">
      <metadata>
        <title>MSN Messenger 4.7 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSN Messenger 4.7</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:4.7"/>
        <description>The application Windows Messenger 4.7 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:33.603-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:25.460-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:41.476-04:00">ACCEPTED</status_change>
            <modified comment="Corrected CPE reference" date="2009-09-25T09:28:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-09-28T04:00:32.074-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:09.298-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3444 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:18.742-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:28.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8484 - corrected platform info" date="2015-04-17T09:36:00.491-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:39:11.566-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:21.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MSN Messenger 4.7 is installed" test_ref="oval:org.mitre.oval:tst:8484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2187" version="5" class="inventory">
      <metadata>
        <title>MSN Messenger 6.2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger 6.2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:6.2"/>
        <description>MSN Messenger 6.2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:03.757-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:14.421-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:11.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2187 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:22.699-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:17.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2187 - Modified MSN Messenger inventories: Fixed product version info" date="2015-04-10T10:01:00.091-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:03:14.287-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MSN Messenger 6.2 is installed" test_ref="oval:org.mitre.oval:tst:4055"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:165" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (x86) Gold is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003::gold:x86"/>
        <description>A version of Microsoft Windows Server 2003 (x86) Gold is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:51.952-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:23.741-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.247-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:23:42.269-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:13.099-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for x86 and windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:08.434-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:165 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:31.979-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:33.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:18.240-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:30.207-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:165 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:38.106-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:11.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows XP SP1 (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp1:x86"/>
        <description>The operating system installed on the system is Microsoft Windows XP SP1 (32-bit).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:14.071-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:17.080-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.732-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:22:08.755-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:09.567-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:26.592-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:03.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
        <criterion negate="true" comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7646" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome before 7.0.517.41 does not properly handle animated GIF images</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4040"/>
        <description>Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:41.072-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:54.266-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:56.123-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:49.547-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:13.121-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:58.613-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:58.299-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:06.841-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:04.860-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:06:47.860-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:57.701-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:30:23.824-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:26.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7637" version="12" class="vulnerability">
      <metadata>
        <title>HTML Sanitization Vulnerability (CVE-2010-3243)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Windows SharePoint Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3243" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3243"/>
        <description>Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:20.402-04:00">DRAFT</status_change>
            <modified comment="Aggregated Def:7637 and Def:7275 due to common CVE." date="2010-11-03T13:43:00.613-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:15.454-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:18.019-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.665-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.665-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:03.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7637 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:44.373-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:37.964-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:36.206-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:30.306-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7637 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:27.805-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Windows XP, Server 2003">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Windows 7, Server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2007">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="the version of Osafehtm.dll is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11537"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criteria operator="OR" comment="Windows Server 2003 32-bit or Windows Server 2003 64-bit">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6545.5002" test_ref="oval:org.mitre.oval:tst:11364"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7633" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in extSetOwner function in UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Trend Micro Internet Security Pro</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3189"/>
        <description>The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-06T09:30:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-06T18:23:41.116-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:31.228-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:53.974-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Trend Micro Internet Security is installed" definition_ref="oval:org.mitre.oval:def:7602"/>
        <criterion comment="Checks if UfPBctrl.dll version is equal to 17.50.0.1366" test_ref="oval:org.mitre.oval:tst:11229"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7602" version="3" class="inventory">
      <metadata>
        <title>Trend Micro Internet Security is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Trend Micro Internet Security Pro</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:trendmicro:internet_security:2010::pro"/>
        <description>Trend Micro Internet Security is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-06T09:30:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-06T18:23:40.731-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:30.797-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:53.076-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
        </criteria>
        <criterion comment="Checks if Trend Micro Internet security Pro is installed" test_ref="oval:org.mitre.oval:tst:11589"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7627" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4036" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4036"/>
        <description>Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:40.587-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:53.694-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:55.759-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:49.265-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:12.751-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:52.734-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:57.885-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:21:57.484-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:04.471-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:06:39.427-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:57.274-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:30:08.206-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:26.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7622" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey window.navigator.plugins Object Dangling Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0177"/>
        <description>Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:02.788-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:58.654-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:45.797-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:39.123-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:06.205-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:31.622-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:15.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7622 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:33.262-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.580-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7622 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:30.698-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:19.867-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:21.228-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:34.207-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.0.19" test_ref="oval:org.mitre.oval:tst:120957"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7620" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome Geolocation Feature Weakness Unspecified Memory Corruption</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3415"/>
        <description>Google Chrome before 6.0.472.59 does not properly implement Geolocation, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:04.244-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:17.195-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:14.273-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:05.781-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:12.299-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:52.415-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:57.498-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:21:56.920-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:03.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:06:37.972-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:56.772-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:30:05.680-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:25.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7618" version="24" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/SeaMonkey XMLDocument::load Function Access Restrictions Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0182"/>
        <description>The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:04.319-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:58.294-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:45.423-04:00">ACCEPTED</status_change>
            <modified comment="Changed [03] to [0-3] in the regex pattern for oval:org.mitre.oval:ste:5296." date="2010-08-11T13:18:00.931-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-11T13:18:53.306-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:15.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:12.604-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:05.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:35.349-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:14.953-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7618 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:12.378-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.450-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5296 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:51.527-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:56.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:28.137-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7618 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7618 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:28.046-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:25.290-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7618 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:19.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:20.876-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:33.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.4" test_ref="oval:org.mitre.oval:tst:114767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7616" version="6" class="vulnerability">
      <metadata>
        <title>Extra Out of Boundary Record Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3239" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3239"/>
        <description>Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:42.326-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:29:00.960-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:15.127-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:17.617-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:00.484-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:35.537-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7615" version="24" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/SeaMonkey Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0174"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:01.822-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:57.884-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:44.969-04:00">ACCEPTED</status_change>
            <modified comment="Changed [03] to [0-3] in the regex pattern for oval:org.mitre.oval:ste:5296." date="2010-08-11T13:18:00.931-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-11T13:18:53.076-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:14.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:13.831-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:05.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:36.252-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:14.465-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7615 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:59.168-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.312-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5296 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:51.656-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:56.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:28.476-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7615 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7615 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:27.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:25.650-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7615 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:19.518-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:21.290-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:33.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.0.19" test_ref="oval:org.mitre.oval:tst:120957"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.4" test_ref="oval:org.mitre.oval:tst:114767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7606" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Hover Event Handling Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1412"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to hover events.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:49.940-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:20.825-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:54.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7606 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:26.739-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:24.926-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:24.295-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:45.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:53.422-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:29.522-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.582-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.740-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7604" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes Log File Insecure File Operation Local Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1768" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1768"/>
        <description>Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T02:48:16">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:24.388-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:16.765-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:13.869-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:50.006-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:30.208-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:41.798-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:13.276-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7604 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:44.250-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:59.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:52:55.880-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:17.904-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:50.729-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:50.025-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7598" version="11" class="vulnerability">
      <metadata>
        <title>Vulnerability in js_InitRandom function in the JavaScript implementation in Mozilla Firefox</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3399"/>
        <description>The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2010-3171.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-21T14:10:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-21T15:40:22.748-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:23.111-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:31.088-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:28.859-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:04.728-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7598 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:25.782-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:19.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:22.916-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:33.467-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Check if Mozilla Firefox version is 3.5.10 through 3.5.11 or 3.6.4 through 3.6.8 or equal to 4.0 Beta1">
          <criterion comment="Mozilla Firefox Mainline version is 3.5.10 through 3.5.11" test_ref="oval:org.mitre.oval:tst:120862"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.6.4 through 3.6.8" test_ref="oval:org.mitre.oval:tst:120921"/>
          <criterion comment="Mozilla Firefox Mainline version is 4.0 Beta1" test_ref="oval:org.mitre.oval:tst:121166"/>
        </criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7593" version="5" class="vulnerability">
      <metadata>
        <title>Excel EDG Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1250" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1250"/>
        <description>Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:52.287-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:50:04.628-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:54.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:01.139-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:34.879-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7591" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Keyboard Focus Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1422"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:47.126-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:20.616-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:54.094-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7591 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:23.204-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:24.587-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:26.327-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:45.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:56.703-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:28.856-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:58.201-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7589" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Image Parsing Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3620"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3629.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:16.016-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:52.609-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:31.908-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:51.112-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:44.656-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:59.503-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:07.806-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:36.909-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:02.812-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:44.166-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:24.732-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:14.336-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:33.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7587" version="9" class="vulnerability">
      <metadata>
        <title>WebKit Nested HTML Tags Use-After-Free Error Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0050"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:39.527-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:57.298-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:44.509-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:25.395-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:44.384-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7587 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:35.970-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:58.983-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:54.901-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:27.727-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7584" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey remote code execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775"/>
        <description>Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:04:49.183-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:09.239-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:47.622-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:40.138-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:03.819-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:36.060-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:04.252-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:15.418-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:13.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7584 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:06.271-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.182-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7584 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:37.248-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:41.616-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7584 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:28.456-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:39.771-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:31.216-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:37.537-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:33.066-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7582" version="6" class="vulnerability">
      <metadata>
        <title>Word Index Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2750" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2750"/>
        <description>Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:30.996-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:22:00.312-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:14.762-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:17.263-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:37.833-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:34.471-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7580" version="13" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in Adobe Flash Player 6.0.79</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0378"/>
        <description>Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-18T02:23:08">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-18T17:08:00.602-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:44.263-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:20.338-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11463 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:26:41.243-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:31.557-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:34.916-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:47.431-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.447-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:27.929-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7580 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-19T15:02:57.275-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:32.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7580 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:41:00.792-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:43:26.750-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:08.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="OS section">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is equal to 6.0.79" test_ref="oval:org.mitre.oval:tst:11463"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx equals 6.0.79" test_ref="oval:org.mitre.oval:tst:123478"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7577" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2185"/>
        <description>Buffer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:43.888-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:50:04.142-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:53.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:23.957-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:24.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:03.731-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7577 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:07.336-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:23.570-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:46.635-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.260-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:57.214-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:05.175-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7577 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:32.670-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7577 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:06.101-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:07.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7576" version="12" class="vulnerability">
      <metadata>
        <title>Wireshark DoS Vulnerability due to IPM dissector</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4378"/>
        <description>The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (crash) via a crafted packet, related to "formatting a date/time using strftime."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-25T10:11:02">
              <contributor organization="SecPod Technologies">Nikita MR</contributor>
            </submitted>
            <status_change date="2010-05-26T09:52:33.605-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:01:01.238-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:03.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7576 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:23.659-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:20.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7019 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:52.985-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:03.425-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7576 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:56:37.948-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:20.901-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7576 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:41.200-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:17.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for Wireshark version 1.2.0 through 1.2.4" test_ref="oval:org.mitre.oval:tst:24197"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7575" version="12" class="vulnerability">
      <metadata>
        <title>Excel File Format Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3232" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3232"/>
        <description>Microsoft Excel 2003 SP3 and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel File Format Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:41.168-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:22.656-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:30.623-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7575 - Modified the definition to check for file &quot;Excelcnv.exe&quot; instead of &quot;Xl12cnv.exe&quot;." date="2011-07-06T09:30:00.476-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-07-06T09:30:31.328-04:00">INTERIM</status_change>
            <status_change date="2011-07-25T04:00:12.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:23:54.985-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:48.480-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:38.902-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:37.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:20.968-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:27.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11422"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11621"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11256"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR" comment="Vulnerable Compatibility Pack, Office 2007">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:43350"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7561" version="17" class="vulnerability">
      <metadata>
        <title>Apple Safari TIFF Image Uninitialized Memory Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple Safari</product>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0042"/>
        <description>ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:37.744-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:56.360-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:43.277-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:49.723-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:29.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:30.813-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:43.482-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:41.450-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:12.871-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7561 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:33.231-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:58.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:35.087-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:16.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:02.810-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:26.852-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:54:00.929-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:49.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check iTunes">
          <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
          <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
        </criteria>
        <criteria operator="AND" comment="Check Safari">
          <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
          <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7556" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Editable Containers Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1398"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document, related to the insertion of an unspecified element into an editable container and the access of an uninitialized element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:47.761-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:20.118-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:53.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7556 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:04.362-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:23.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:34.813-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:42.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:08.701-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:26.179-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.908-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.544-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7555" version="6" class="vulnerability">
      <metadata>
        <title>Formula Substream Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3234" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3234"/>
        <description>Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:43.450-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:21:00.676-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:14.476-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:16.887-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:06.756-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:31.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7554" version="9" class="vulnerability">
      <metadata>
        <title>WebKit Cross-Origin Stylesheet Request Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0051"/>
        <description>WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document.  NOTE: this might overlap CVE-2010-0651.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:39.684-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:55.912-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:42.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:34.585-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:42.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7554 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:17.378-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:58.165-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:08.359-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:25.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7553" version="7" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Google Earth version 5.1.3535.3218</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Earth</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3134"/>
        <description>Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll that is located in the same folder as a .kmz file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T05:48:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:34:45.394-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:43.895-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:30.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7272 - Now checking HKLM\SOFTWARE\Google\GoogleEarthPlugin which is removed after deinstallation." date="2013-09-20T13:16:00.983-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-20T13:32:15.123-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:13.568-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11355 - check=&quot;all&quot; was replased with check=&quot;at least one&quot; because all objects have the set of objects." date="2014-03-21T13:14:00.094-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-21T13:18:27.538-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:57.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Google Earth installed is equal to 5.1.3535.3218" test_ref="oval:org.mitre.oval:tst:11355"/>
        <extend_definition comment="Google Earth is installed" definition_ref="oval:org.mitre.oval:def:6838"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6838" version="7" class="inventory">
      <metadata>
        <title>Google Earth is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Earth</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:google:earth"/>
        <description>Google Earth is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T05:48:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:34:45.079-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:37.610-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:19.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11367 - Now checking HKLM\SOFTWARE\Google\GoogleEarthPlugin which is removed after deinstallation." date="2013-09-20T13:16:00.983-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-20T13:32:14.286-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:04.778-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11367 - check=&quot;all&quot; was replased with check=&quot;at least one&quot; because all objects have the set of objects." date="2014-03-21T13:14:00.094-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-21T13:18:05.096-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:56.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Google Earth is installed" test_ref="oval:org.mitre.oval:tst:11367"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7552" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTML Fragment Cross Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1394" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1394"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML document fragments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:46.754-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:19.858-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:53.271-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7552 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:18.658-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:23.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:33.912-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:41.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:07.368-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:24.575-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.659-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.448-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7546" version="24" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/SeaMonkey nsTreeSelection Use-After-Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0175"/>
        <description>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:02.208-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:55.535-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:42.413-04:00">ACCEPTED</status_change>
            <modified comment="Changed [03] to [0-3] in the regex pattern for oval:org.mitre.oval:ste:5296." date="2010-08-11T13:18:00.931-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-11T13:18:53.166-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:14.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:06.766-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:03.678-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:42.613-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:13.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7546 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:55:03.993-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:52.032-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5296 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:52.114-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:55.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:46.552-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7546 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7546 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:27.669-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:44.422-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7546 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:19.122-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:43.088-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:32.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is before 3.0.19" test_ref="oval:org.mitre.oval:tst:120962"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.4" test_ref="oval:org.mitre.oval:tst:114767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7544" version="3" class="vulnerability">
      <metadata>
        <title>MySQL 6.0 and 5.1 XPath Expression DOS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 6.0</product>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0819"/>
        <description>sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-22T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-27T13:49:19.093-05:00">DRAFT</status_change>
            <status_change date="2010-02-15T04:00:04.171-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:10.723-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6533 - &quot;\&quot; was removed before &quot;_&quot; and regular expressions were simplified" date="2013-10-17T12:07:00.149-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:08:35.513-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:23.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="MySQL 6.0 is installed" definition_ref="oval:org.mitre.oval:def:7563"/>
          <criterion comment="MySQL Server 6.0 version is less than 6.0.10" test_ref="oval:org.mitre.oval:tst:20906"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
          <criterion comment="MySQL Server 5.1 version is less than 5.1.32" test_ref="oval:org.mitre.oval:tst:21013"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7563" version="15" class="inventory">
      <metadata>
        <title>MySQL 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:mysql:mysql:6.0"/>
        <description>MySQL Server 6.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-22T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-27T13:49:17.441-05:00">DRAFT</status_change>
            <status_change date="2010-02-15T04:00:04.487-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:11.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7563 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:45.191-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:42.078-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:349 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:47.783-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:43.855-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7563 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:14.463-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:26.387-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:911 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:11.433-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:30.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11786 - new inventory and platforms for MySQL 5.6" date="2014-09-11T08:17:00.634-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-11T08:19:27.448-04:00">INTERIM</status_change>
            <status_change date="2014-09-29T04:00:27.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11992 - Added 32-bit windows view" date="2014-10-24T13:20:00.601-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:20:46.832-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:36.345-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7563 - Corrected comments" date="2015-05-12T14:28:00.183-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2015-05-12T14:32:02.728-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:23.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MySQL 6.0 is installed" test_ref="oval:org.mitre.oval:tst:20984"/>
        <criterion comment="mysqld.exe or mysqld-nt.exe exists" test_ref="oval:org.mitre.oval:tst:21031"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7543" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1288" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1288"/>
        <description>Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:47.500-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:37.119-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:24.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:07.776-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:36.088-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7529" version="6" class="vulnerability">
      <metadata>
        <title>Word Bookmarks Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3216" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3216"/>
        <description>Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:33.997-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:22:00.881-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:13.870-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:16.547-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:38.457-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:30.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7528" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Invalid Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2174"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, related to an "invalid pointer vulnerability" and the newfunction (0x44) operator, a different vulnerability than CVE-2010-2173.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:40.946-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:50:01.510-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:52.890-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:30.980-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:23.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:12.969-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7528 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:06.819-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:50.514-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:45.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:07.387-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:57.073-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:08.075-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7528 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:32.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7528 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:11.793-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:07.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7523" version="10" class="vulnerability">
      <metadata>
        <title>Apple Quicktime QTPlugin.ocx ActiveX IPersistPropertyBag2::Read Function _Marshaled_pUnk Memory Corruption</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1818"/>
        <description>The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshaling of an untrusted pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-16T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-16T11:38:41.503-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:43.390-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:29.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:10.807-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:41.586-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:39.153-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:31.037-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7523 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:36.125-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:57.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.8 (7.68.75.0)" test_ref="oval:org.mitre.oval:tst:11363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7519" version="11" class="vulnerability">
      <metadata>
        <title>WebKit SVG 'use' Element Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1403"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during the handling of a use element in an SVG document, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document containing XML that triggers a parsing error, related to ProcessInstruction.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:48.619-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:19.649-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:52.671-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7519 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:26.056-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:22.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:22.943-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:40.890-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:51.389-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:22.349-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.066-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.276-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7517" version="15" class="vulnerability">
      <metadata>
        <title>Media Decompression Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Windows Media Format Runtime 9.0</product>
          <product>Windows Media Format Runtime 9.5</product>
          <product>Windows Media Format Runtime 11</product>
          <product>Quartz.dll (DirectShow)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1879" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1879"/>
        <description>Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "Media Decompression Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:41.939-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:59.464-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:51.420-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7517 - Made updates to the criteria, as there were references to a few tests that are unnecessary." date="2011-03-03T20:50:00.988-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-03T20:52:01.367-05:00">INTERIM</status_change>
            <status_change date="2011-03-21T04:00:16.212-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.619-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.619-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:02.043-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:32.439-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:46.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:01.526-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:23.741-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:02.735-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:27.184-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7517 - extended definitions of OS are without SP checks" date="2014-07-28T17:51:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:52:48.685-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:29.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 / Quartz in DirectX 9.0">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.914" test_ref="oval:org.mitre.oval:tst:27014"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) / Quartz">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3665" test_ref="oval:org.mitre.oval:tst:27701"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) / Quartz">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5933" test_ref="oval:org.mitre.oval:tst:27719"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64 / Quartz">
          <criteria operator="OR" comment="Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4660" test_ref="oval:org.mitre.oval:tst:27493"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.18461" test_ref="oval:org.mitre.oval:tst:27630"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.22672" test_ref="oval:org.mitre.oval:tst:27567"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.22000" test_ref="oval:org.mitre.oval:tst:20940"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Media Format Runtime 9.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.0 is installed." test_ref="oval:org.mitre.oval:tst:125"/>
          <criterion comment="the version of Wmvcore.dll is less than 9.0.0.3369" test_ref="oval:org.mitre.oval:tst:27090"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Media Format Runtime 9.0 on Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.0 is installed." test_ref="oval:org.mitre.oval:tst:125"/>
          <criterion comment="the version of Wmvcore.dll is less than 9.0.0.3272" test_ref="oval:org.mitre.oval:tst:27165"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
          <criterion comment="the version of Wmvcore.dll is less than 10.0.0.3706" test_ref="oval:org.mitre.oval:tst:27502"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
          <criterion comment="the version of Wmvcore.dll is less than 11.0.5721.5275" test_ref="oval:org.mitre.oval:tst:27010"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.0 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.0 is installed." test_ref="oval:org.mitre.oval:tst:125"/>
          <criterion comment="the version of Wmvcore.dll is less than 9.0.0.4509" test_ref="oval:org.mitre.oval:tst:26916"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
          <criterion comment="the version of Wmvcore.dll is less than 10.0.0.3706" test_ref="oval:org.mitre.oval:tst:27502"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
          <criterion comment="the version of Wmvcore.dll is less than 11.0.5721.5275" test_ref="oval:org.mitre.oval:tst:27010"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 on x64-bit platform is installed." test_ref="oval:org.mitre.oval:tst:10154"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\Wmvcore.dll is less than 10.0.0.4007" test_ref="oval:org.mitre.oval:tst:27378"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 on x64-bit platform is installed." test_ref="oval:org.mitre.oval:tst:10083"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\Wmvcore.dll is less than 11.0.5721.5275" test_ref="oval:org.mitre.oval:tst:27758"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows Server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
          <criterion comment="the version of Wmvcore.dll is less than 10.0.0.4007" test_ref="oval:org.mitre.oval:tst:27501"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows Server 2003 x64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 on x64-bit platform is installed." test_ref="oval:org.mitre.oval:tst:10154"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\Wmvcore.dll is less than 10.0.0.4007" test_ref="oval:org.mitre.oval:tst:27378"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Encoder 9, 32-bit version">
          <criteria operator="OR" comment="Microsoft Windows 2000, XP x86, Server 2003 x86, Vista x86, Server 2008 32bit">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="the version of Wmenceng.dll is greater than or equal to 9.0.0.0" test_ref="oval:org.mitre.oval:tst:27572"/>
          <criterion comment="the version of Wmenceng.dll is less than 9.0.0.3369" test_ref="oval:org.mitre.oval:tst:27755"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Encoder 9 WOW, 64-bit version">
          <criteria operator="OR" comment="Microsoft Windows XP x64, Server 2003 x64, Vista x64, Server 2008 64bit">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="the version of Program Files (x86)\Windows Media Components\Encoder\Wmenceng.dll is greater than or equal to 9.0.0.0" test_ref="oval:org.mitre.oval:tst:26968"/>
          <criterion comment="the version of Program Files (x86)\Windows Media Components\Encoder\Wmenceng.dll is less than 9.0.0.3369" test_ref="oval:org.mitre.oval:tst:27159"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Encoder 9, 64-bit version">
          <criteria operator="OR" comment="Microsoft Windows XP x64, Server 2003 x64, Vista x64, Server 2008 64bit">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="the version of Wmenceng.dll is greater than or equal to 10.0.0.0" test_ref="oval:org.mitre.oval:tst:27289"/>
          <criterion comment="the version of Wmenceng.dll is less than 10.0.0.3821" test_ref="oval:org.mitre.oval:tst:27748"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 / Asycfilt.dll (COM component)">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of Asycfilt.dll is less than 2.40.4534.0" test_ref="oval:org.mitre.oval:tst:27520"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) / Asycfilt.dll (COM component)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Asycfilt.dll is less than 5.1.2600.3680" test_ref="oval:org.mitre.oval:tst:27671"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) / Asycfilt.dll (COM component)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Asycfilt.dll is less than 5.1.2600.5949" test_ref="oval:org.mitre.oval:tst:27534"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64 / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows XP x64, Server 2003 x64/x86/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 5.2.3790.4676" test_ref="oval:org.mitre.oval:tst:27532"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows Vista x64/x86, Server 2008 32bit/64bit/ia-64 Gold">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 6.0.6001.18454" test_ref="oval:org.mitre.oval:tst:27637"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows Vista x64/x86, Server 2008 32bit/64bit/ia-64 Gold">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 6.0.6001.22665" test_ref="oval:org.mitre.oval:tst:27614"/>
          <criterion comment="the version of Asycfilt.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:27662"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows Vista SP2 x64/x86, Server 2008 32bit/64bit/ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 6.0.6002.18236" test_ref="oval:org.mitre.oval:tst:26971"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows Vista SP2 x64/x86, Server 2008 32bit/64bit/ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 6.0.6002.22377" test_ref="oval:org.mitre.oval:tst:27708"/>
          <criterion comment="the version of Asycfilt.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:27233"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows 7 x64/x86, Server 2008 R2 x64/ia-64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 6.1.7600.16544" test_ref="oval:org.mitre.oval:tst:27766"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR / Asycfilt.dll (COM component)">
          <criteria operator="OR" comment="Microsoft Windows 7 x64/x86, Server 2008 R2 x64/ia-64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Asycfilt.dll is less than 6.1.7600.20660" test_ref="oval:org.mitre.oval:tst:26956"/>
          <criterion comment="the version of Asycfilt.dll is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7516" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey Memory corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304"/>
        <description>The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:07:05.962-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:58.694-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:39.111-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:19.476-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:03.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:02.399-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:12.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7516 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:50.223-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.898-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7516 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:33.671-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:29.965-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7516 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:26.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:27.198-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:29.637-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:23.086-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:31.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7514" version="10" class="vulnerability">
      <metadata>
        <title>Win32k Keyboard Layout Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2743"/>
        <description>The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability."  NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:41.987-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:21.593-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:29.904-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7514 - Replaced duplicate extended definition def:6216 (Windows server 2008 x64 Edition SP2 is installed) with def:5594 (Vista x64 SP2 is installed)" date="2011-07-14T12:58:00.638-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-07-14T13:02:18.465-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:58.945-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.900-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.900-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:01.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:01.166-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:23.511-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.6033" test_ref="oval:org.mitre.oval:tst:11527"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4769" test_ref="oval:org.mitre.oval:tst:11544"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR" comment="Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18523" test_ref="oval:org.mitre.oval:tst:11810"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22754" test_ref="oval:org.mitre.oval:tst:11488"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18305" test_ref="oval:org.mitre.oval:tst:11583"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22478" test_ref="oval:org.mitre.oval:tst:11508"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16667" test_ref="oval:org.mitre.oval:tst:11343"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20792" test_ref="oval:org.mitre.oval:tst:11609"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7513" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 QDMC Encoded Audio Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0060"/>
        <description>CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:57.565-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:55.328-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:42.162-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:05.559-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:40.565-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:42.625-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:30.560-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7513 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:09.201-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:56.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7508" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Exhaustion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2160"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an invalid offset in an unspecified undocumented opcode in ActionScript Virtual Machine 2, related to getouterscope, a different vulnerability than CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:37.287-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:58.519-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:50.971-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:31.746-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:22.319-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:13.815-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7508 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:06.387-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:16.591-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:45.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:12.065-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:56.909-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:08.419-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7508 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:31.769-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7508 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:16.387-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:07.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7507" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in an ActiveX control in the Internet Explorer (IE) plugin in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
          <product>RealPlayer SP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3001"/>
        <description>Unspecified vulnerability in an ActiveX control in the Internet Explorer (IE) plugin in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows has unknown impact and attack vectors related to "multiple browser windows."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:26.342-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:16.415-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:13.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer SP is greater than or equal to 1.0" test_ref="oval:org.mitre.oval:tst:11442"/>
            <criterion comment="Check if the version of RealPlayer SP is less than 1.1.5" test_ref="oval:org.mitre.oval:tst:11165"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
            <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7504" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1295"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:20.528-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:50.428-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:16.342-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:10.872-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:31.434-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:53.585-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:39.838-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:01.852-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:05.763-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:39.233-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:01.974-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:47.487-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:24.002-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7503" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTML Document textarea Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1762"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML in a TEXTAREA element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.257-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:19.422-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:50.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7503 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:22.099-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:21.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:25.617-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:39.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:55.453-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:20.932-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:58.046-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.191-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7501" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Multiple Vulnerabilities that could lead to code execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2163"/>
        <description>Multiple unspecified vulnerabilities in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:38.533-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:58.212-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:49.820-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:33.084-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:21.565-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:15.413-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7501 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:05.324-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:22.596-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:44.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.093-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:56.768-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:09.078-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7501 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:31.580-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7501 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:12.502-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:07.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7500" version="18" class="vulnerability">
      <metadata>
        <title>Buffer Overflow Vulnerability in Adobe Download Manager, used in Adobe Reader and Acrobat</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1278" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1278"/>
        <description>Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x before 9.3, allows remote attackers to execute arbitrary code via unspecified parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-14T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-14T10:30:07.928-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:36.669-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:23.186-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:12.138-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:30.890-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:58.372-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:38.439-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:05.425-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:04.695-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:43.341-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:01.328-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:56.923-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:23.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20925"/>
            <criterion comment="Adobe Reader library is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20935"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20920"/>
            <criterion comment="Adobe Reader library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.0" test_ref="oval:org.mitre.oval:tst:20943"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.1" test_ref="oval:org.mitre.oval:tst:20897"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.0" test_ref="oval:org.mitre.oval:tst:20616"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7499" version="11" class="vulnerability">
      <metadata>
        <title>ColorSync in Apple Safari Heap Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1726"/>
        <description>Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.989-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:19.213-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:49.561-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7499 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:06.055-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:21.238-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:19.273-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:37.904-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:45.906-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:20.314-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.438-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:06.099-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7498" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 FlashPix Encoded Movie Handling Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0519"/>
        <description>Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:56.418-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:54.616-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:41.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:03.175-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:37.576-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:39.676-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:30.242-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7498 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:14.116-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:55.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7497" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Option Recursive Use Element Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1404"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:48.932-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:18.960-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:49.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7497 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:20.392-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:20.844-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:20.258-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:37.181-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:47.222-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:19.189-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:56.135-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.994-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7494" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0203"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0202.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:40.448-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:54.208-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:40.846-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.481-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:30.413-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:41.441-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:35.929-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:47.412-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:03.980-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:25.427-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:04:00.650-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:25.276-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:22.636-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7492" version="8" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Microsoft Internet Explorer 8 Developer Tools Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0811" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0811"/>
        <description>Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:54.627-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:57.286-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:48.737-04:00">ACCEPTED</status_change>
            <modified comment="I found when installing KB2508272 (Def:12534) update, the KB2508272 update also includes the update KB980195 (Def:7492). I've added the criteria from def:7492 to def:12534." date="2011-05-23T15:02:39.881-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-05-23T15:02:39.881-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12235 - registry key was pointing to invalid CLSID" date="2011-07-14T10:16:00.951-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:52.228-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27459"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27590"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7491" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Multiple Heap Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2167"/>
        <description>Multiple heap-based buffer overflows in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to malformed (1) GIF or (2) JPEG data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:39.609-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:56.916-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:48.361-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:32.430-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:20.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:14.614-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7491 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:03.546-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:18.097-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:43.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:12.229-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:56.508-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:08.689-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7491 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:31.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7491 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:09.723-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:06.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7484" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3656" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3656"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3657.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:20.470-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:51.619-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:29.919-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:49.074-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:35.068-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:55.406-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:02.947-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:32.977-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:59.969-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:39.421-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:21.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:13.575-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:31.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7482" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-3329)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3329" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3329"/>
        <description>mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:23.256-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:20.713-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:28.986-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:55.728-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:55.728-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:00.467-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:03.695-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:23.231-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7482 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:29.997-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:29.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7477" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player 3D Parsing Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0127"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:44.768-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:36.393-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:22.844-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:05.351-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:35.854-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7476" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTML Tables Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1774"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses out-of-bounds memory during processing of HTML tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.834-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:18.756-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:48.138-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7476 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:06.595-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:20.121-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:08.137-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:34.514-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:30.706-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:18.381-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:51.998-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.901-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7475" version="6" class="vulnerability">
      <metadata>
        <title>Excel Record Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3231" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3231"/>
        <description>Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:43.917-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:30:00.793-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:13.587-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:16.231-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:53.791-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:29.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7470" version="3" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Adobe Captivate version 5.0.0.596 via a Trojan horse dwmapi.dll</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Captivate</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3191"/>
        <description>Untrusted search path vulnerability in Adobe Captivate 5.0.0.596, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .cptx file.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-13T05:18:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-13T04:00:15.847-05:00">INTERIM</status_change>
            <status_change date="2011-01-03T04:00:33.086-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Captivate is installed" definition_ref="oval:org.mitre.oval:def:6982"/>
        <criterion comment="Check if Adobe Captivate version is equal to 5.0.0.596" test_ref="oval:org.mitre.oval:tst:11071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6982" version="5" class="inventory">
      <metadata>
        <title>Adobe Captivate is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Captivate</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:adobe:captivate"/>
        <description>Adobe Captivate is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-13T05:18:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-13T04:00:13.110-05:00">INTERIM</status_change>
            <status_change date="2011-01-03T04:00:32.237-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6982 - modified inventories for Microsoft Expression Design." date="2013-07-05T09:53:00.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:58:03.933-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:11.632-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Adobe Captivate is installed" test_ref="oval:org.mitre.oval:tst:11299"/>
        <criterion comment="The registry key that holds the fullpath of Adobe Captivate exists" test_ref="oval:org.mitre.oval:tst:81520"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7467" version="24" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/SeaMonkey Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0173"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:01.457-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:53.526-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:40.460-04:00">ACCEPTED</status_change>
            <modified comment="Changed [03] to [0-3] in the regex pattern for oval:org.mitre.oval:ste:5296." date="2010-08-11T13:18:00.931-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-11T13:18:53.227-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:13.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:15.424-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:02.538-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:30.316-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:12.016-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7467 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:52.430-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.762-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5296 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:51.782-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:55.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:38.914-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7467 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7467 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:27.444-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:37.124-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7467 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:18.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:34.289-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:30.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.4" test_ref="oval:org.mitre.oval:tst:114767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7466" version="20" class="vulnerability">
      <metadata>
        <title>Adobe Reader 9.3.1 on Windows does not restrict the contents of one text field in the Launch File warning dialog</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1240" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1240"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-14T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-14T10:30:02.757-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:36.104-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:22.179-04:00">ACCEPTED</status_change>
            <modified comment="Updated the criteria to include relevant products and versions." date="2010-07-02T09:50:00.804-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-07-02T09:51:12.879-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:47.373-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.296-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:29.400-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:33.441-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:33.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:33.382-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:02.341-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:12.253-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:59.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:07.278-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:21.276-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7465" version="14" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR JPEG File Parsing Heap Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3794"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:33.678-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:32.918-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:05.355-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:09.122-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:53.162-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:41.230-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:29.763-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:50.118-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:42.787-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:07.210-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:56.368-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:20.790-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7465 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:30.704-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7465 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:09.941-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:06.723-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7464" version="11" class="vulnerability">
      <metadata>
        <title>WebKit DOM Constructor Cross Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1395" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1395"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving DOM constructor objects, related to a "scope management issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:47.286-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:18.334-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:47.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7464 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:21.529-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:19.742-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:14.631-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:33.362-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:40.148-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:16.401-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:53.890-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.815-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7462" version="9" class="vulnerability" deprecated="true">
      <metadata>
        <title>Google Chrome Document API Parsing Use-after-free DoS</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3408"/>
        <description>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1823.  Reason: This candidate is a duplicate of CVE-2010-1823.  Notes: All CVE users should reference CVE-2010-1823 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:02.969-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:16.120-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:12.918-04:00">ACCEPTED</status_change>
            <modified comment="Deprecated - definition was duplicate of CVE-2010-1823, please refer to that CVE." date="2010-11-22T12:00:00.000-05:00">
              <contributor organization="Critical Watch">Nelson Bunker</contributor>
            </modified>
            <status_change date="2010-11-22T12:00:00.000-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7460" version="14" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Data Injection Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3796"/>
        <description>Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:33.903-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:32.604-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:04.947-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:09.503-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:52.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:39.854-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:29.168-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:51.675-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:42.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:19.297-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:56.230-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:20.382-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7460 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:30.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7460 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:16.181-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:06.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7458" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 PICT Image Handling Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0527"/>
        <description>Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:55.900-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:52.555-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:40.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:04.484-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:32.695-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:41.118-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:28.640-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7458 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:19.625-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:55.163-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7455" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Arbitrary Code Execution and Denial of Service  Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3628"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3632, and CVE-2010-3658.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:18.531-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:50.953-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:28.902-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:41.945-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:31.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:28.449-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:01.565-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:02.857-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:58.607-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:26.845-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:20.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:13.879-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:30.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7438" version="9" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in UltraPlayer Media Player 2.112</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>UltraPlayer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4863"/>
        <description>Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-17T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-17T15:31:35.525-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:39.388-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:17.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:883 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:42.225-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:31.450-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:38.989-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:46.254-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:21.416-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:26.791-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="UltraPlayer 2.112">
          <extend_definition comment="UltraPlayer is installed" definition_ref="oval:org.mitre.oval:def:7035"/>
          <criterion comment="Check if UltraPlayer is 2.112" test_ref="oval:org.mitre.oval:tst:11322"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7035" version="3" class="inventory">
      <metadata>
        <title>UltraPlayer is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>UltraPlayer</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:ultraplayer:ultraplayer_media_player"/>
        <description>UltraPlayer is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-17T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-17T15:31:35.229-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:23.237-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:09.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if UltraPlayer is installed" test_ref="oval:org.mitre.oval:tst:11054"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7435" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey Phishing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777"/>
        <description>Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:05:21.524-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:47.785-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:30.957-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:42.408-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:02.983-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:46.706-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:02.009-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:23.469-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:11.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7435 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:53:55.998-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.586-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7435 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:38.784-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:43.288-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7435 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:25.798-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:41.289-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:28.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:39.203-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:30.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7431" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2166"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:39.349-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:52.337-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:46.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:24.677-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:19.377-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:05.124-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7431 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:04:01.110-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:25.822-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:41.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.651-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:56.073-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:05.454-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7431 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:29.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7431 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:10.903-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:06.328-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7427" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes MP4 File Processing Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0531"/>
        <description>Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:38.171-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:51.822-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:39.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:49.165-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:29.555-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:40.759-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:12.555-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7427 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:53.007-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:54.718-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:34.331-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:16.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:54:00.700-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:49.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7420" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Font Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0195"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:37.696-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:51.411-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:38.714-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.373-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:28.410-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:34.752-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:30.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:19.000-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:04:00.496-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:54.134-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:57.931-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:08.761-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:19.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7417" version="9" class="vulnerability">
      <metadata>
        <title>Anchor Element Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3327" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3327"/>
        <description>The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, aka "Anchor Element Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:21.654-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:19.747-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:28.111-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.212-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.212-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:59.572-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:10.241-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.837-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7417 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.326-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:28.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7416" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player PAMI Chunk Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1292"/>
        <description>The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:48.310-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:35.744-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:21.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.926-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:35.663-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7415" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2176"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:41.509-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:51.814-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:46.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:29.334-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:18.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:10.915-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7415 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:59.840-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:11.384-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:40.494-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:10.933-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:55.930-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.464-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7415 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:29.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7415 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:16.790-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:06.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7410" version="9" class="vulnerability">
      <metadata>
        <title>CSS Special Character Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3325" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3325"/>
        <description>Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a crafted web site, aka "CSS Special Character Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:19.271-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:18.769-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:27.148-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:58.652-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.029-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.546-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7410 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:32.943-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:27.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7406" version="11" class="vulnerability">
      <metadata>
        <title>Memory Corruption Vulnerability (CVE-2010-1262)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1262"/>
        <description>Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:19.562-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:49.906-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:45.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:13.824-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:57.305-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.290-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.290-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:57.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:12.822-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.250-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7406 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.978-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:27.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1649" test_ref="oval:org.mitre.oval:tst:27761"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3698" test_ref="oval:org.mitre.oval:tst:27446"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5969" test_ref="oval:org.mitre.oval:tst:27626"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4696" test_ref="oval:org.mitre.oval:tst:27176"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7405" version="13" class="vulnerability">
      <metadata>
        <title>Vulnerability in WebKit used in Google Chrome version less than 6.0.472.59 via vectors related to SVG font,aka rdar problem 8442098</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1823"/>
        <description>Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-30T08:37:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:13.246-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:12.148-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:18.411-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:07.434-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:11.908-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:50.871-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:57.131-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:21:54.140-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:03.518-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:06:34.813-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:56.338-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:30:00.222-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:19.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7403" version="9" class="vulnerability">
      <metadata>
        <title>WebKit HTML Elements Callback Use-After-Free Error Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0052"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "callbacks for HTML elements."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:39.850-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:51.199-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:38.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:27.636-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:29.656-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7403 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:21.755-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:54.370-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:58.376-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:15.566-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7401" version="11" class="vulnerability">
      <metadata>
        <title>WebKit SVG Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1416"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict the reading of a canvas that contains an SVG image pattern from a different web site, which allows remote attackers to read images from other sites via a crafted canvas, related to a "cross-site image capture issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:50.614-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:17.771-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:45.198-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7401 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:02.648-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:18.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:25.935-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:28.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:56.157-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:14.787-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:58.131-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.719-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7397" version="9" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow vulnerability in IrfanView related to PSD image</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>IrfanView</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1510"/>
        <description>Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-19T03:34:03">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2010-05-19T10:10:23.417-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:38.224-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:17.469-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:409 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:57.127-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:28.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:54.554-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:41.925-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:08.695-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:25.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="IrfanView is installed" definition_ref="oval:org.mitre.oval:def:7162"/>
        <criteria operator="OR">
          <criterion comment="IrfanView display version is less than 4.27" test_ref="oval:org.mitre.oval:tst:11566"/>
          <criterion comment="IrfanView binary version is less than 4.27" test_ref="oval:org.mitre.oval:tst:11511"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7393" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service and Arbitrary Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3630"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:19.344-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:48.860-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:27.918-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:25.803-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:27.696-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:07.431-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:59.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:45.102-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:57.313-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:50.622-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:18.683-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:13.428-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:29.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7390" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey security bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776"/>
        <description>nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:05:02.658-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:41.115-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:26.723-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:39.655-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:02.510-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:30.523-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:01.522-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:15.320-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:11.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7390 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:50.428-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.443-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7390 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:39.670-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.132-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:05.641-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7390 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:25.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:01.262-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:27.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:53.943-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:29.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7388" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Infinite Loop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1282"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted ATOM size in a .dir (aka Director) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:46.467-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:35.480-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:20.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.633-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:35.337-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7387" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0204"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:40.793-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:50.753-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:37.781-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.069-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:27.436-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:31.885-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:26.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:14.165-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:58.683-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:50.536-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:56.634-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:01.435-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:17.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7386" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3621"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:16.451-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:48.462-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:26.937-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:32.408-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:25.943-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:15.156-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:58.108-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:51.132-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:55.925-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:02.168-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:17.204-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.679-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:29.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7385" version="19" class="vulnerability">
      <metadata>
        <title>Memory Corruption via unspecified vectors vulnerability in Adobe Reader and Acrobat.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3619"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:15.663-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:48.066-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:26.489-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:31.065-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:25.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:13.114-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:57.506-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:49.972-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:55.314-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:59.928-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:16.513-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.387-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:28.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7382" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Font Parsing Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3626"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-2889.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:17.584-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:47.400-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:25.985-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:47.507-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:24.520-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:53.749-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:56.890-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:30.782-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:54.659-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:36.129-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:15.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.953-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:28.704-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7380" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome SPDY Protocol Implementation Buffer Management Weakness Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3729"/>
        <description>The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers, which might allow remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-10-08T16:39:36.004-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:29.170-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:47.106-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7143 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:32.923-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:11.583-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:59:00.979-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:56.679-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:36.824-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:03.121-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:07:17.889-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:55.851-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:31:14.747-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:14.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.62" test_ref="oval:org.mitre.oval:tst:11067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7378" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Untrusted search path vulnerability in ATL MFC Trace Tool as used in Microsoft Visual Studio 2010</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Studio</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3190"/>
        <description>Untrusted search path vulnerability in ATL MFC Trace Tool (AtlTraceTool8.exe), as used in Microsoft Visual Studio, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a TRC, cur, rs, rct, or res file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T10:02:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-12T21:14:27.996-04:00">DRAFT</status_change>
            <status_change date="2010-11-01T04:00:12.619-04:00">INTERIM</status_change>
            <status_change date="2010-11-22T04:00:13.282-05:00">ACCEPTED</status_change>
            <modified comment="Deprecated due to April 2011 Patch Tuesday" date="2011-04-18T00:27:47.404-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-04-18T00:27:47.404-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of AtlTraceTool8.exe in Microsoft Visual Studio 2010 installed is equal to 10.0.30319.1" test_ref="oval:org.mitre.oval:tst:11421"/>
        <extend_definition comment="Microsoft Visual Studio 2010 is installed" definition_ref="oval:org.mitre.oval:def:7533"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7375" version="6" class="vulnerability">
      <metadata>
        <title>Word Boundary Check Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2748" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2748"/>
        <description>Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:30.784-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:25:00.547-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:12.943-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:15.519-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:34.086-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:28.951-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7374" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'libxml' Context Handling Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1415"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml contexts, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to an "API abuse issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:50.450-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:17.264-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:44.927-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7374 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:08.916-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:17.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:18.901-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:23.960-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:45.516-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:13.928-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.510-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.628-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7371" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome Extension History Access Prompting Weakness Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3417"/>
        <description>Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:04.459-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:15.759-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:12.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:07.151-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:11.242-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:59:01.365-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:56.324-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:45.924-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:02.703-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:07:30.569-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:55.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:31:35.418-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:14.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7370" version="11" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Math.random function in the JavaScript implementation in Mozilla Firefox</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3171" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3171"/>
        <description>The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-21T14:10:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-21T15:40:22.994-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:18.074-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:26.734-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:41.659-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:01.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7370 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:38.480-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:18.689-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.577-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:28.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Check if Mozilla Firefox version is 3.5.10 before 3.5.11 or 3.6.4 before 3.6.8 or 4.0 Beta1">
          <criterion comment="Mozilla Firefox Mainline version is 3.5.10 through 3.5.11" test_ref="oval:org.mitre.oval:tst:120862"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.6.4 through 3.6.8" test_ref="oval:org.mitre.oval:tst:120921"/>
          <criterion comment="Mozilla Firefox Mainline version is 4.0 Beta1" test_ref="oval:org.mitre.oval:tst:121166"/>
        </criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7369" version="5" class="vulnerability">
      <metadata>
        <title>Excel String Variable Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1252" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1252"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:51.829-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:48.951-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:44.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:02.938-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:28.413-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7364" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2178"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:42.093-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:47.834-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:44.324-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:29.665-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:17.333-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:11.353-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7364 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:56.442-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:11.852-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:39.288-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:11.022-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:55.706-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.581-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7364 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:28.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7364 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:07.976-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:05.699-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7360" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>BlackBerry Desktop Software</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3741"/>
        <description>The offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software uses single-iteration PBKDF2, which makes it easier for local users to decrypt a .ipd file via a brute-force attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-26T10:43:26">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:33.530-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:46.801-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.000-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7140 - Added 32 bit behavior" date="2015-08-06T11:25:00.053-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-06T11:27:54.786-04:00">INTERIM</status_change>
            <status_change date="2015-08-24T04:00:07.064-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="BlackBerry Desktop Software is installed" definition_ref="oval:org.mitre.oval:def:6688"/>
        <criterion comment="Check if BlackBerry Desktop Software version is less than or equal to 6.0.0.43" test_ref="oval:org.mitre.oval:tst:21407"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7358" version="5" class="vulnerability">
      <metadata>
        <title>Print Spooler Service Impersonation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2729" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2729"/>
        <description>The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:38:52.863-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:42.626-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:28.425-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:56.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:56.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:56.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Spoolsv.exe version is less than 5.1.2600.6024" test_ref="oval:org.mitre.oval:tst:11063"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Spoolsv.exe version is less than 5.2.3790.4759" test_ref="oval:org.mitre.oval:tst:10999"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Spoolsv.exe version is less than 6.0.6001.18511" test_ref="oval:org.mitre.oval:tst:11637"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11237"/>
              <criterion comment="Spoolsv.exe version is less than 6.0.6001.22743" test_ref="oval:org.mitre.oval:tst:11293"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Spoolsv.exe version is less than 6.0.6002.18294" test_ref="oval:org.mitre.oval:tst:11534"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spoolsv.exe version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11602"/>
              <criterion comment="Spoolsv.exe version is less than 6.0.6002.22468" test_ref="oval:org.mitre.oval:tst:11035"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Spoolsv.exe version is less than 6.1.7600.16661" test_ref="oval:org.mitre.oval:tst:11090"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spoolsv.exe version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11311"/>
              <criterion comment="Spoolsv.exe version is less than 6.1.7600.20785" test_ref="oval:org.mitre.oval:tst:11301"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7356" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3627" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3627"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:18.167-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:46.382-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:25.544-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:25.290-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:23.393-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:16.207-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:55.890-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:41:59.978-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:54.058-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:49.925-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:13.685-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:13.276-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:28.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7354" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome Console Implementation Race Condition Unspecified Issue</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3412"/>
        <description>Race condition in the console implementation in Google Chrome before 6.0.472.59 has unspecified impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:03.685-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:15.471-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:11.797-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:06.538-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:10.799-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:59.970-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:55.919-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:09.609-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:02.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:06:49.675-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:54.803-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:30:27.652-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:13.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7352" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0193"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0196.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:36.941-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:50.206-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:36.751-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:05.098-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:25.079-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:26.824-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:22.418-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:18.142-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:55.350-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:01.496-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:53.215-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:52.005-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:12.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7348" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat ActiveX Multiple Input Validation Code Execution Vulnerabilities.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2888" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2888"/>
        <description>Multiple unspecified vulnerabilities in an ActiveX control in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Windows allow attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:14.528-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:45.908-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:24.617-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:36.945-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:21.595-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:37.761-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:54.755-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:16.578-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:52.543-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:13.656-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:11.828-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:14.698-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:27.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7347" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTTP Redirect Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1764"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, follows multiple redirections during form submission, which allows remote web servers to obtain sensitive information by recording the form data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.410-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:16.988-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:44.097-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7347 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:09.479-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:16.949-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:14.138-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:21.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:39.691-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:13.364-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:53.958-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.543-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7346" version="11" class="vulnerability">
      <metadata>
        <title>WebKit CSS Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1393"/>
        <description>The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to discover sensitive URLs via an HREF attribute associated with a redirecting URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:46.587-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:16.765-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:43.835-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7346 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:24.868-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:16.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:13.783-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:20.635-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:39.295-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:12.476-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:53.823-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.457-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7342" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2181"/>
        <description>Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2170 and CVE-2010-2183.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:42.856-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:47.258-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:43.207-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:29.983-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:16.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:11.769-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7342 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:54.330-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:49.307-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:38.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:06.909-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:55.581-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.695-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7342 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:27.716-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7342 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:05.647-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:05.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7339" version="15" class="vulnerability">
      <metadata>
        <title>Vulnerability in js_InitRandom function in the JavaScript implementation in Mozilla Firefox and Seamonkey</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3400" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3400"/>
        <description>The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-21T14:10:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-21T15:40:22.247-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:17.691-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:26.404-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:00.880-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:04:00.677-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11851 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:06:26.879-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:10.496-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7339 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:23.900-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.314-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7339 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:32.389-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:18.492-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.347-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:27.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check if Mozilla Firefox version is 3.5.x before 3.5.10 or 3.6.x before 3.6.4 and installed or not">
          <criteria operator="OR" comment="Check if Mozilla Firefox either version 3.5.x before 3.5.10 or 3.6.x before 3.6.4 is installed">
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.10" test_ref="oval:org.mitre.oval:tst:120668"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.4" test_ref="oval:org.mitre.oval:tst:121139"/>
          </criteria>
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        </criteria>
        <criteria operator="AND" comment="Check if Mozilla Seamonkey version is 2.0.x before 2.0.5">
          <criterion comment="Check if Mozilla Seamonkey version is before 2.0.5" test_ref="oval:org.mitre.oval:tst:99723"/>
          <criterion comment="Determine if the version of Mozilla Seamonkey is greater than or equal to 2.0" test_ref="oval:org.mitre.oval:tst:100051"/>
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7336" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2202"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:21.603-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:42.760-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:15.816-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.225-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:23.978-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:42.973-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:19.944-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:30.778-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:53.755-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:04.521-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:51.918-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:28.214-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:11.150-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7335" version="11" class="vulnerability">
      <metadata>
        <title>WebKit DOM Range Objects Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1758"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving DOM Range objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:51.761-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:16.558-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:42.526-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7335 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:05.472-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:15.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:36.807-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:19.489-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:11.288-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:11.407-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:56.583-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.367-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7334" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2184"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:43.634-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:46.850-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:42.197-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:24.998-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:15.357-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:05.516-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7334 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:53.345-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:49.452-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:37.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:18.765-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:55.428-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:05.584-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7334 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:27.288-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7334 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:07.147-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:05.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7331" version="11" class="vulnerability">
      <metadata>
        <title>Wireshark DoS Vulnerability due to DOCSIS dissector</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1455"/>
        <description>The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-19T15:11:12">
              <contributor organization="SecPod Technologies">Nikita MR</contributor>
            </submitted>
            <status_change date="2010-05-19T10:10:30.816-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:36.473-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:16.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7331 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:15.788-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:19.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6769 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:53.780-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:02.109-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7331 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:56:38.704-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:20.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7331 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:17.438-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:15.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for Wireshark version 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7" test_ref="oval:org.mitre.oval:tst:11839"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7328" version="5" class="vulnerability">
      <metadata>
        <title>Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 5.0</product>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1849"/>
        <description>The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:42.456-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:15.875-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:41.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7196 - &quot;\&quot; was removed before &quot;_&quot; and regular expressions were simplified" date="2013-10-17T12:07:00.149-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:08:37.218-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:10.873-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.0 is installed" definition_ref="oval:org.mitre.oval:def:8282"/>
          <criterion comment="MySQL Server 5.0 version is less than 5.0.91" test_ref="oval:org.mitre.oval:tst:27183"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
          <criterion comment="MySQL Server 5.1 version is less than 5.1.47" test_ref="oval:org.mitre.oval:tst:27571"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7326" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
          <product>RealPlayer SP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0116"/>
        <description>Integer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows might allow remote attackers to execute arbitrary code via a crafted QCP file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:25.237-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:14.776-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:11.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer SP is greater than or equal to 1.0" test_ref="oval:org.mitre.oval:tst:11442"/>
            <criterion comment="Check if the version of RealPlayer SP is less than 1.1.5" test_ref="oval:org.mitre.oval:tst:11165"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
            <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7324" version="11" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-1259)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1259" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1259"/>
        <description>Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:12.647-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:44.204-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:40.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:07.127-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:56.029-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:54.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.667-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7324 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:30.366-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:26.869-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1649" test_ref="oval:org.mitre.oval:tst:27761"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3698" test_ref="oval:org.mitre.oval:tst:27446"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5969" test_ref="oval:org.mitre.oval:tst:27626"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4696" test_ref="oval:org.mitre.oval:tst:27176"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7323" version="9" class="vulnerability">
      <metadata>
        <title>WebKit CSS 'run-in' Display Use-After-Free Error Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0053"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:40.008-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:49.954-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:36.241-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:41.850-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:18.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7323 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:16.755-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:53.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:18.056-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:10.386-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7322" version="13" class="vulnerability">
      <metadata>
        <title>Word Stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
          <product>Microsoft Word 2003</product>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Word 2010</product>
          <product>Microsoft Office Word Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3214" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3214"/>
        <description>Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Word Viewer; Office Web Apps; and Word Web App allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Stack Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:33.391-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:17.184-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:25.867-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1517 - In obj:1517 for Office Word Viewer is updated by adding new variable and object to make it work. Earlier obj:1517 was referring to OfficeWord object path" date="2011-07-18T15:27:00.494-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-18T15:28:23.295-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:55.437-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6394 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:19.659-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11522 - Updating Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:51:00.071-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:41.227-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15263 - added new criteria and 32 bit checks." date="2013-01-31T09:01:00.731-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-31T09:03:32.707-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:33.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:30.187-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:25.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2002">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
        </criteria>
        <criteria operator="AND" comment="Word 2003">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of Winword.exe is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11358"/>
        </criteria>
        <criteria operator="AND" comment="Word 2007">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="the version of Winword.exe is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11470"/>
        </criteria>
        <criteria operator="AND" comment="Word 2010">
          <extend_definition comment="Microsoft Word 2010 is installed" definition_ref="oval:org.mitre.oval:def:7631"/>
          <criterion comment="the version of winword.exe is less than 14.0.5123.5000" test_ref="oval:org.mitre.oval:tst:11522"/>
        </criteria>
        <criteria operator="AND" comment="Word Viewer">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of Wordview.exe is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11354"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="the version of Wordcnv.dll is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11368"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7315" version="23" class="vulnerability">
      <metadata>
        <title>TLS/SSL Renegotiation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:03.754-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:49.620-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:35.805-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:51.759-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.759-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:54.126-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:44.716-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:59.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:24.158-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:09.537-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5296 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:51.914-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:55.027-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:42.668-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7315 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7315 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:27.006-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7315 - extended definitions of OS are without SP checks" date="2014-07-28T17:34:00.316-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:36:12.884-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7315 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:18.120-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:38.780-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:26.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Seamonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100858"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.4" test_ref="oval:org.mitre.oval:tst:114767"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2600.6006" test_ref="oval:org.mitre.oval:tst:40676"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.4724" test_ref="oval:org.mitre.oval:tst:41575"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6001.18490" test_ref="oval:org.mitre.oval:tst:41364"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:41291"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6001.22709" test_ref="oval:org.mitre.oval:tst:41584"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6002.18269" test_ref="oval:org.mitre.oval:tst:41449"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:41611"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6002.22422" test_ref="oval:org.mitre.oval:tst:41666"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.1.7600.16612" test_ref="oval:org.mitre.oval:tst:41572"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:41670"/>
              <criterion comment="the version of schannel.dll is less than 6.1.7600.20735" test_ref="oval:org.mitre.oval:tst:41407"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7314" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Use After Free Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1419"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a certain window close action that occurs during a drag-and-drop operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:51.135-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:15.660-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:40.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7314 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:16.312-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:14.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:28.830-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:18.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:59.974-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:09.672-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:52.261-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.271-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7313" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome Document Origin Properties Pollution Unspecified Issue</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3730"/>
        <description>Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-10-08T16:39:35.774-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:26.695-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:44.569-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7143 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:32.625-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:10.470-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:59:01.808-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:55.565-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:47.888-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:01.872-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:07:33.974-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:54.389-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:31:41.316-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:10.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.62" test_ref="oval:org.mitre.oval:tst:11067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7303" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Out Of Bounds Memory Indexing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2161"/>
        <description>Array index error in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified "types of Adobe Flash code."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:37.904-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:41.519-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:39.795-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:30.337-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:14.620-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:12.207-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7303 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:52.888-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:39.062-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:36.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:16.245-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:55.289-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.838-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7303 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:26.736-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7303 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:14.329-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:04.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7298" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0197"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:38.593-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:49.212-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:35.375-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:12.055-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:23.515-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:57.851-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:17.608-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:46.384-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:52.305-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:19.311-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:51.305-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:56.274-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:09.850-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7297" version="13" class="vulnerability">
      <metadata>
        <title>HTML Sanitization Vulnerability (CVE-2010-3324)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Windows SharePoint Services 3.0</product>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Office SharePoint Foundation 2010</product>
          <product>Microsoft Groove Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3324" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3324"/>
        <description>The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:20.888-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:16.531-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:25.251-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7297 - include MS10-072. CVE-2010-3324 applies to two Microsoft Bulletins, MS10-072 and MS10-071" date="2011-12-05T13:38:00.474-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-12-05T13:40:42.850-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:02:55.270-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.009-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.009-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:52.733-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7297 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:51.749-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:36.592-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:38.333-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:07.649-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7297 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:33.874-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:26.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64,XP x86, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Windows 7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criteria operator="OR" comment="Windows Server 2003 32-bit or Windows Server 2003 64-bit">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6545.5002" test_ref="oval:org.mitre.oval:tst:11364"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="the version of Onetutil.dll is less than 14.0.5123.5001" test_ref="oval:org.mitre.oval:tst:77271"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2007">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="the version of Osafehtm.dll is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11537"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Groove Server 2010">
          <extend_definition comment="Microsoft Groove Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:12278"/>
          <criterion comment="Groovems.dll version is less than 14.0.5123.5000" test_ref="oval:org.mitre.oval:tst:77367"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7295" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Non-default TCP Port Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1408"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to bypass intended restrictions on outbound connections to "non-default TCP ports" via a crafted port number, related to an "integer truncation issue." NOTE: this may overlap CVE-2010-1099.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:49.466-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:15.446-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:39.552-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7295 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:07.790-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:14.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:34.266-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:17.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:07.854-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:06.994-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.828-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:05.073-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7291" version="7" class="vulnerability">
      <metadata>
        <title>Privilege-escalation vulnerability in PostgreSQL version less than or equal to 9.0</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PostgreSQL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3433" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3433"/>
        <description>The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-21T11:57:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-21T15:40:27.460-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:15.923-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:24.705-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6960 - var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-10-29T16:13:00.745-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-29T16:15:35.530-04:00">INTERIM</status_change>
            <status_change date="2013-11-14T10:21:30.660-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11725 - Added 32-bit branch and corrected check" date="2015-03-06T14:46:00.120-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-06T14:48:45.145-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:34.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Check if PostgreSQL version is 7.4.x, 8.0.x,8.1.x, 8.2.x,8.3.x, 8.4.x or 9.0.0">
          <criteria operator="AND" comment="Check if PostgreSQL version is 7.4.x series">
            <criterion comment="Check if PostgreSQL version  is 7.4.x series" test_ref="oval:org.mitre.oval:tst:11631"/>
            <criterion comment="Check if PostgreSQL version is less than 7.4.30" test_ref="oval:org.mitre.oval:tst:11658"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.0.x series">
            <criterion comment="Check if PostgreSQL version is less than  8.0.26" test_ref="oval:org.mitre.oval:tst:11930"/>
            <criterion comment="Check if PostgreSQL version is 8.0.x series" test_ref="oval:org.mitre.oval:tst:11909"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 9.0.x series">
            <criterion comment="Check if PostgreSQL version is 9.0.x series" test_ref="oval:org.mitre.oval:tst:11640"/>
            <criterion comment="Check if PostgreSQL version is less than  9.0.1" test_ref="oval:org.mitre.oval:tst:11717"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.1.x series">
            <criterion comment="Check if PostgreSQL version is less than  8.1.22" test_ref="oval:org.mitre.oval:tst:11673"/>
            <criterion comment="Check if PostgreSQL version is 8.1.x series" test_ref="oval:org.mitre.oval:tst:11725"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.2.x series">
            <criterion comment="Check if PostgreSQL version is less than  8.2.18" test_ref="oval:org.mitre.oval:tst:11680"/>
            <criterion comment="Check if PostgreSQL version is 8.2.x series" test_ref="oval:org.mitre.oval:tst:11744"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.3.x series">
            <criterion comment="Check if PostgreSQL version is less than  8.3.12" test_ref="oval:org.mitre.oval:tst:11689"/>
            <criterion comment="Check if PostgreSQL version is 8.3.x series" test_ref="oval:org.mitre.oval:tst:11778"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.4.x series">
            <criterion comment="Check if PostgreSQL version is less than  8.4.5" test_ref="oval:org.mitre.oval:tst:11766"/>
            <criterion comment="Check if PostgreSQL version is 8.4.x series" test_ref="oval:org.mitre.oval:tst:11913"/>
          </criteria>
        </criteria>
        <extend_definition comment="PostgreSQL is installed" definition_ref="oval:org.mitre.oval:def:6785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7288" version="12" class="vulnerability">
      <metadata>
        <title>WebKit Option Element 'ContentEditable' Attribute Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1396"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the contentEditable attribute and removing container elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:47.442-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:15.234-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:39.336-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7288 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:02.099-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:13.924-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:39.882-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:16.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:15.510-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:05.999-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.385-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.985-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7286" version="26" class="vulnerability">
      <metadata>
        <title>COM Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office XP</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft PowerPoint 2003</product>
          <product>Microsoft Publisher 2003</product>
          <product>Microsoft Visio 2003</product>
          <product>Microsoft Word 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft PowerPoint 2007</product>
          <product>Microsoft Publisher 2007</product>
          <product>Microsoft Visio 2007</product>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Wordpad</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1263" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1263"/>
        <description>Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; Microsoft Office XP SP3; Office 2003 SP3; and Office System 2007 SP1 and SP2 do not properly validate COM objects during instantiation, which allows remote attackers to execute arbitrary code via a crafted file, aka "COM Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:31.139-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:37.181-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:38.543-04:00">ACCEPTED</status_change>
            <modified comment="Updated definition to include wordpad." date="2010-10-18T21:12:00.073-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-10-18T21:16:28.480-04:00">INTERIM</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:36:00.937-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:10.846-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:58.759-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:58.759-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:51.323-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:04.351-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:850 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:6394 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:var:297 - Updating Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:51:00.071-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:39.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27489 - Updates to Visio related definitions to fix Object collection concerns." date="2013-01-22T15:55:00.810-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-22T16:11:12.672-05:00">INTERIM</status_change>
            <status_change date="2013-02-11T04:03:49.608-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23570 - the value of the parameter var_check was changed to at least one." date="2013-09-11T09:57:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:00:08.651-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:35.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7286 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:18.658-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:33.387-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:10.295-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:24.858-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7286 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:12.760-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23570 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-08-18T04:06:26.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
        <criteria operator="AND" comment="Microsoft Office 2007">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Mso.dll version is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27214"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office 2003">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="Mso.dll version is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27418"/>
        </criteria>
        <criteria operator="AND" comment="Word 2007">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="the version of Winword.exe is less than 12.0.6535.5000" test_ref="oval:org.mitre.oval:tst:27739"/>
        </criteria>
        <criteria operator="AND" comment="Word 2003">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of Winword.exe is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27649"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office Visio 2007">
          <extend_definition comment="Microsoft Office Visio 2007 is installed" definition_ref="oval:org.mitre.oval:def:5261"/>
          <criterion comment="Vislib.dll version is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27489"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office Visio 2003">
          <extend_definition comment="Microsoft Office Visio 2003 is installed" definition_ref="oval:org.mitre.oval:def:1450"/>
          <criterion comment="Vislib.dll version is less than 11.0.8323.0" test_ref="oval:org.mitre.oval:tst:27608"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft PowerPoint 2007">
          <extend_definition comment="Microsoft PowerPoint 2007 is installed" definition_ref="oval:org.mitre.oval:def:5937"/>
          <criterion comment="ppcore.dll version is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27184"/>
        </criteria>
        <criteria operator="AND" comment="Publisher 2007">
          <extend_definition comment="Microsoft Publisher 2007 is installed" definition_ref="oval:org.mitre.oval:def:2127"/>
          <criterion comment="the version of Mspub.exe is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27543"/>
        </criteria>
        <criteria operator="AND" comment="Publisher 2003">
          <extend_definition comment="Microsoft Publisher 2003 is installed" definition_ref="oval:org.mitre.oval:def:239"/>
          <criterion comment="the version of Mspub.exe is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27728"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="Powerpnt.exe is less than version 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27674"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27234"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:20930"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wordpad.exe is less than 5.1.2600.6010" test_ref="oval:org.mitre.oval:tst:11545"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64 or 2003 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of wordpad.exe is less than 5.2.3790.4750" test_ref="oval:org.mitre.oval:tst:11122"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR" comment="Vista x86\x64 or 2008 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of wordpad.exe is less than 6.0.6001.18498" test_ref="oval:org.mitre.oval:tst:11505"/>
            <criterion comment="The version of Msshsq.dll is less than 6.0.6001.18470" test_ref="oval:org.mitre.oval:tst:11166"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of wordpad.exe is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11123"/>
              <criterion comment="the version of wordpad.exe is less than 6.0.6001.22720" test_ref="oval:org.mitre.oval:tst:11327"/>
            </criteria>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Msshsq.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11395"/>
              <criterion comment="The version of Msshsq.dll is less than 6.0.6001.22685" test_ref="oval:org.mitre.oval:tst:11386"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR" comment="Vista x86\x64 or 2008 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of wordpad.exe is less than 6.0.6002.18277" test_ref="oval:org.mitre.oval:tst:11404"/>
            <criterion comment="The version of Msshsq.dll is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:11660"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of wordpad.exe is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11510"/>
              <criterion comment="the version of wordpad.exe is less than 6.0.6002.22433" test_ref="oval:org.mitre.oval:tst:11474"/>
            </criteria>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Msshsq.dll is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11543"/>
              <criterion comment="The version of Msshsq.dll is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:11408"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86\x64 or 2008R2 x64\ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of wordpad.exe is less than 6.1.7600.16624" test_ref="oval:org.mitre.oval:tst:11156"/>
            <criterion comment="the version of Structuredquery.dll version is less than 7.0.7600.16587" test_ref="oval:org.mitre.oval:tst:11575"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of wordpad.exe is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11485"/>
              <criterion comment="the version of wordpad.exe is less than 6.1.7600.20744" test_ref="oval:org.mitre.oval:tst:11370"/>
            </criteria>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Structuredquery.dll is greater than or equal to 7.0.7600.20000" test_ref="oval:org.mitre.oval:tst:11671"/>
              <criterion comment="The version of Structuredquery.dll is less than 7.0.7600.20707" test_ref="oval:org.mitre.oval:tst:11172"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7285" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird, Firefox and Seamonkey XSS and arbitrary injection Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1308"/>
        <description>Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:08:40.701-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:35.515-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:22.850-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:52.360-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:59.157-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:36.710-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:08.872-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7285 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:55:05.283-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.197-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7285 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:36.225-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:33.062-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:09.805-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7285 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:24.587-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:05.768-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:25.809-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:58.914-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:26.499-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7284" version="3" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in Free Download Manager (FDM).</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Free Download Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0999"/>
        <description>Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-20T03:34:03">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2010-05-21T09:03:25.855-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:34.818-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:14.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Free Download Manager">
          <extend_definition comment="Free Download Manager is installed" definition_ref="oval:org.mitre.oval:def:6797"/>
          <criterion comment="Free Download Manager binary version is less than 3.0.852.0" test_ref="oval:org.mitre.oval:tst:11305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7283" version="9" class="vulnerability">
      <metadata>
        <title>Win32k TrueType Font Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1255"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:25.000-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:36.500-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:37.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7283 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:59:00.878-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T16:00:06.146-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:13.412-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:50.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:57.050-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.536-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16585" test_ref="oval:org.mitre.oval:tst:27474"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20704" test_ref="oval:org.mitre.oval:tst:27593"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7278" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2183"/>
        <description>Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2170 and CVE-2010-2181.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:43.388-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:36.172-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:37.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:33.402-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:13.571-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:15.941-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7278 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:51.606-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:46.205-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:35.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:17.851-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:55.127-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:09.243-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7278 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:26.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7278 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:12.739-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:04.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7276" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Pointer Memory Corruption</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2169" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2169"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allow attackers to cause a denial of service (pointer memory corruption) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:39.855-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:35.816-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:36.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:32.112-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:13.220-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:14.224-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7276 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:51.168-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:44.097-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:34.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:17.331-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:54.850-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:08.551-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7276 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:26.189-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7276 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:17.019-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:04.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7275" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>HTML Sanitization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Windows SharePoint Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3243"/>
        <description>Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:30.253-04:00">DRAFT</status_change>
            <status_change date="2010-11-03T14:29:32.570-04:00">DEPRECATED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.470-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7275 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2007">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="the version of Osafehtm.dll is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11537"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criteria operator="OR" comment="Windows Server 2003 32-bit or Windows Server 2003 64-bit">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6545.5002" test_ref="oval:org.mitre.oval:tst:11364"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7273" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0128"/>
        <description>Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:44.985-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:35.221-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:19.100-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:05.623-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:35.132-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7272" version="7" class="vulnerability">
      <metadata>
        <title>Comctl32 Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2746" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2746"/>
        <description>Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:55.409-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:15.250-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:23.979-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7272 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:41.354-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:46.442-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:49.654-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows XP SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.2900.6028" test_ref="oval:org.mitre.oval:tst:11533"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 sp2, Server 2003 x86/x64/ia64 sp2">
          <criteria operator="OR" comment="Microsoft Windows XP x64 Edition SP2, Server 2003 SP2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="The version of Comctl32.dll is less than 5.82.3790.4770" test_ref="oval:org.mitre.oval:tst:11557"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 sp1, Windows Server 2008 x86/x64, Windows Server 2008 ia64">
          <criteria operator="OR" comment="Microsoft Windows Vista SP1 x64/32-bit, Server 2008 32-bit/64-bit/ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.6001.18523" test_ref="oval:org.mitre.oval:tst:11561"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.6001.22000" test_ref="oval:org.mitre.oval:tst:11519"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.6001.22755" test_ref="oval:org.mitre.oval:tst:11516"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 sp2, Windows Server 2008 x86/x64 sp2, Windindows Server 2008 ia64 sp2">
          <criteria operator="OR" comment="Microsoft Windows Vista SP2 32-bit/x64, Server 2008 SP2 32-bit/x64/Itanium">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.6002.18305" test_ref="oval:org.mitre.oval:tst:11513"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.6002.22000" test_ref="oval:org.mitre.oval:tst:11503"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.6002.22480" test_ref="oval:org.mitre.oval:tst:11494"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 7 x86/x64, Windows 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows 7 32-bit/x64, Server 2008 R2 x64/Itanium">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.7600.16661" test_ref="oval:org.mitre.oval:tst:11441"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.7600.20000" test_ref="oval:org.mitre.oval:tst:11432"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.7600.20787" test_ref="oval:org.mitre.oval:tst:11728"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7271" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Stack Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1866" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1866"/>
        <description>Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:32.150-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:31.929-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:44:00.787-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:10.359-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:49.369-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:27.955-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:24.440-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:34.111-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.412-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:26.566-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7271 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-19T15:02:58.285-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:26.022-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7271 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:06.903-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:04.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123306"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:123732"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7269" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1286"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:47.128-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:34.922-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:18.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:07.199-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:34.902-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7268" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Director File Parsing Invalid Offset Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1281"/>
        <description>iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:46.270-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:34.659-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:18.479-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.794-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:34.717-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7266" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2187"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:44.399-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:35.512-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:36.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:27.371-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:12.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:08.344-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7266 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:50.677-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:33.966-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:33.308-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.275-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:54.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.626-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7266 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:25.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7266 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:12.270-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:04.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7265" version="5" class="vulnerability">
      <metadata>
        <title>Excel Object Stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0822" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0822"/>
        <description>Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:54.734-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:35.236-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:36.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:05.454-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:26.351-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7262" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player 3D Object Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1283"/>
        <description>Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:46.683-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:34.388-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:18.053-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.480-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:34.542-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7255" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Plain Text NTLM Credentials Passing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1413" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1413"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in unspecified circumstances, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:50.132-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:14.554-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:36.105-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7255 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:25.460-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:12.405-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:10.373-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:15.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:33.718-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:03.994-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:52.381-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.899-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7252" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Custom Vertical Positioning Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1405" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1405"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:49.136-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:14.322-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:35.823-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7252 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:01.519-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:12.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:09.382-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:14.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:32.486-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:03:02.200-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:52.142-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.812-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7242" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2204"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:21.946-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:35.115-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:15.345-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.446-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:22.987-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:35.996-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:14.338-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:36.568-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:50.108-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:15.341-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:48.812-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:09.999-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:09.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7240" version="12" class="vulnerability">
      <metadata>
        <title>Excel Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0823" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0823"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-1247 and CVE-2010-1249.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:54.364-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:32.800-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:34.329-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27720 - Updated to check for Excelcnv.exe as vulnerable &amp; not Xl12cnv.exe file according to the MS Bulletin.  Also updated comments." date="2011-07-28T13:55:00.826-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-29T10:25:03.935-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:11.211-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:01.250-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:38.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:46.376-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:34.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:17.436-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:24.384-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27579"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27680"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6535.5000" test_ref="oval:org.mitre.oval:tst:27301"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR" comment="Check for Office 2007 or Compatibility Pack">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6535.5000" test_ref="oval:org.mitre.oval:tst:27720"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7235" version="10" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Seamonkey Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311"/>
        <description>Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:09:31.510-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:31.612-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:19.498-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:26.835-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:58.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:09.472-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:08.430-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7235 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:09.166-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:51.064-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7235 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:40.424-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:32.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:99880"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7227" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in RealNetworks RealPlayer 11.0 through 11.1 allows attackers to bypass intended access restrictions on files via unknown vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3002"/>
        <description>Unspecified vulnerability in RealNetworks RealPlayer 11.0 through 11.1 allows attackers to bypass intended access restrictions on files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:26.623-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:14.485-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:10.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="AND">
          <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
          <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7225" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3658"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, and CVE-2010-3632.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:20.119-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:42.708-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:22.553-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:49.567-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:13.632-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:56.589-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:49.493-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:33.630-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:48.179-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:40.009-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:08.476-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:14.040-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:25.626-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7224" version="8" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Microsoft Windows Contacts via a Trojan horse wab32res.dll</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows Contacts</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3143"/>
        <description>Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .contact, .group, .p7c, .vcf, or .wab file.  NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3147.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-13T15:19:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-13T04:00:15.201-05:00">INTERIM</status_change>
            <status_change date="2011-01-03T04:00:32.723-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:30.965-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:38.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:18.892-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:24.240-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Check if wab.exe file present in Microsoft Windows Vista and Server 2008 version is less than or equal to 6.0.6000.16386" test_ref="oval:org.mitre.oval:tst:11523"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          </criteria>
          <criterion comment="Check if wab.exe file present in Microsoft Windows 7 version is less than or equal to 6.1.7600.16385" test_ref="oval:org.mitre.oval:tst:11228"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7223" version="5" class="vulnerability">
      <metadata>
        <title>Excel HFPicture Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1248" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1248"/>
        <description>Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:52.705-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:31.644-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:33.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:03.328-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:25.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7222" version="24" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox/Thunderbird/SeaMonkey XUL Tree Optgroup Dangling Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0176"/>
        <description>Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:02.494-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:48.082-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:33.800-04:00">ACCEPTED</status_change>
            <modified comment="Changed [03] to [0-3] in the regex pattern for oval:org.mitre.oval:ste:5296." date="2010-08-11T13:18:00.931-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-11T13:18:53.431-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:13.544-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:37.443-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:58.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:43.134-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:07.854-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7222 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:19.958-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.909-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5296 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:52.254-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:54.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:41.778-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7222 - I remaked the leftover definitions" date="2014-06-20T11:23:00.617-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7222 - replaced all links to oval:org.mitre.oval:def:6504" date="2014-06-25T16:25:00.999-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-14T04:01:26.644-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:39.881-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7222 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:17.858-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:37.671-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:25.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.0.19" test_ref="oval:org.mitre.oval:tst:120957"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Thunderbird Mainline">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Mozilla Thunderbird version less than 3.0.4" test_ref="oval:org.mitre.oval:tst:114767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7221" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes Webkit Unspecified Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1763"/>
        <description>Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T02:48:16">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:25.562-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:14.155-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:10.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:51.518-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:29.160-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:43.727-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:12.136-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7221 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:48.455-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:53.475-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7221 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:51:17.968-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:15.266-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:58.480-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:49.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.2.0.61" test_ref="oval:org.mitre.oval:tst:11571"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7217" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes DLL Loading Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1795" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1795"/>
        <description>Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote attackers to gain privileges via a Trojan horse DLL in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T02:48:16">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:24.074-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:13.740-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:09.935-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:50.371-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:28.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:42.394-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:11.681-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7217 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:52.292-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:52.926-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:27.545-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:14.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:59.067-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:48.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Affected operating system">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
        </criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7210" version="5" class="vulnerability">
      <metadata>
        <title>Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 5.0</product>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1848"/>
        <description>Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:42.205-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:13.954-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:33.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7196 - &quot;\&quot; was removed before &quot;_&quot; and regular expressions were simplified" date="2013-10-17T12:07:00.149-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:08:37.600-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:57.276-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.0 is installed" definition_ref="oval:org.mitre.oval:def:8282"/>
          <criterion comment="MySQL Server 5.0 version is less than 5.0.91" test_ref="oval:org.mitre.oval:tst:27183"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
          <criterion comment="MySQL Server 5.1 version is less than 5.1.47" test_ref="oval:org.mitre.oval:tst:27571"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7209" version="5" class="vulnerability">
      <metadata>
        <title>Out Of Bounds Array Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3236" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3236"/>
        <description>Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:42.956-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:14.551-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:23.311-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:06.415-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:25.249-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11422"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7205" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Exhaustion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3793" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3793"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory consumption) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:36.986-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:30.442-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:33.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:30.656-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:11.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:12.591-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7205 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:48.988-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:39.495-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:32.553-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:16.328-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:54.305-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.956-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7205 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:25.242-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7205 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:11.494-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:03.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7202" version="13" class="vulnerability">
      <metadata>
        <title>Vulnerability in WebKit used in Google Chrome version less than 6.0.472.59 via vectors related to nested SVG elements</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1825"/>
        <description>Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to nested SVG elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-30T08:37:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:12.764-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:11.777-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:13.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:06.118-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:10.136-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:59:02.811-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:55.208-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:51.112-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:01.464-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:07:40.368-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:53.894-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:31:53.498-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:07.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7200" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Array-indexing Error Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2206"/>
        <description>Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image in a PDF file, which bypasses a size check and triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:22.718-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:32.824-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:14.808-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.227-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:22.012-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:32.894-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:12.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:15.631-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:48.419-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:51.648-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:47.510-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:03.584-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:06.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7199" version="11" class="vulnerability">
      <metadata>
        <title>Apple Safari PDF Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1385"/>
        <description>Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:45.523-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:13.736-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:32.591-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7199 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:20.936-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:11.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:26.645-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:12.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:57.182-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:55.534-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:58.453-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.721-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7197" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTTPS Referer Header Passing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1406"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging, a related issue to CVE-2010-0660.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:49.306-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:13.530-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:32.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7197 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:27.338-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:11.044-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:26.975-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:11.889-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:57.604-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:53.361-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:58.549-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.636-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7196" version="12" class="vulnerability">
      <metadata>
        <title>Real Time Data Array Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3240" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3240"/>
        <description>Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Real Time Data Array Record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:41.921-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:13.434-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:22.503-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7196 - Modified the definition to check for file &quot;Excelcnv.exe&quot; instead of &quot;Xl12cnv.exe&quot;." date="2011-07-06T09:28:00.479-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-07-06T09:30:04.843-04:00">INTERIM</status_change>
            <status_change date="2011-07-25T04:00:11.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:23:56.577-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:35.966-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:40.917-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:33.914-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:01.936-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:23.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11621"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11256"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:43311"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7195" version="7" class="vulnerability">
      <metadata>
        <title>Remote code execution vulnerability in Canonical Display Driver</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3678"/>
        <description>Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-19T11:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-05-19T15:51:02.110-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:33.356-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:13.297-04:00">ACCEPTED</status_change>
            <modified comment="Added new file tests in the def:7195 to check for cdd.dll version" date="2010-07-14T17:39:00.479-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-07-14T17:43:02.526-04:00">INTERIM</status_change>
            <status_change date="2010-08-02T04:00:09.795-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.572-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.572-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:49.240-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="GDR or LDR update has been applied">
          <criterion comment="Cdd.dll version is less than 6.1.7600.16595" test_ref="oval:org.mitre.oval:tst:40738"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Cdd.dll version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:40644"/>
            <criterion comment="Cdd.dll version is less than 6.1.7600.20715" test_ref="oval:org.mitre.oval:tst:40259"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7193" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability via a Trojan horse mfc90loc.dll in avast! Free Antivirus version less than or equal to 5.0.594</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>avast! Free Antivirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3126"/>
        <description>Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc90loc.dll that is located in the same folder as an avast license (.avastlic) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T14:44:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:07.134-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:13.449-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:09.632-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:16.559-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:11.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criteria operator="OR">
          <criterion comment="Checks if avast! Free Antivirus version is less than or equal to 5.0.594.0" test_ref="oval:org.mitre.oval:tst:11045"/>
          <criterion comment="Checks if avast! Free Antivirus version is less than or equal to 4.8.1367.0" test_ref="oval:org.mitre.oval:tst:11285"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7191" version="14" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR 'exception_count' Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3799"/>
        <description>Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:34.645-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:31.615-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:04.310-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:10.103-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:47.477-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:40.281-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:27.180-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:56.201-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:31.884-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:08.239-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:54.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:20.504-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7191 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:25.100-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7191 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:05.872-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:03.750-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7188" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Dereference Deleted Heap Object Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2208"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:23.467-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:31.868-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:14.344-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.786-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:21.525-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:45.909-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:10.603-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:52.077-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:47.812-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:29.655-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:46.782-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:33.235-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:05.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7187" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player SWF Version Null Pointer Dereference Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4546"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:45.719-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:29.895-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:31.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:26.369-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:10.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:07.174-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7187 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:47.360-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:07.257-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:31.367-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:10.156-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:54.014-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.128-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7187 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:24.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7187 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:13.463-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:03.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7186" version="5" class="vulnerability">
      <metadata>
        <title>SMB Client Incomplete Response Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3676"/>
        <description>The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:03.269-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:46.998-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:33.004-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.478-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.478-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:48.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7184" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player DIR File Parsing Remote Code Execution Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1280" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1280"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:46.060-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:34.115-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:16.900-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:08.013-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:34.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7183" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1291" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1291"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1290.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:48.127-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:33.802-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:16.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:08.081-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:34.058-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7182" version="9" class="vulnerability">
      <metadata>
        <title>ActiveX control in NOS Microsystems getPlus Download Manager Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Download Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0189"/>
        <description>A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-14T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-14T10:29:59.810-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:33.348-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:16.351-04:00">ACCEPTED</status_change>
            <modified comment="Changed comment in tst:117733, pattern and comment in obj:7245, literal component of var:59 and added ste in tst:117733" date="2010-09-30T12:05:00.302-04:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2010-09-30T12:31:07.530-04:00">INTERIM</status_change>
            <status_change date="2010-10-18T04:00:11.445-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:49.148-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:35.329-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:07.474-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:23.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if getPlus version is less than or equal to 1.6.2.60" test_ref="oval:org.mitre.oval:tst:11773"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7180" version="11" class="vulnerability">
      <metadata>
        <title>WebKit SVG 'RadialGradient' Attribute Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1749"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Cascading Style Sheets (CSS) run-in property and multiple invocations of a destructor for a child element that has been referenced multiple times.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:51.461-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:13.072-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:31.288-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7180 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:03.786-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:09.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:31.443-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:10.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:03.855-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:51.477-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:54.352-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.544-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7178" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes Crafted itpc: URL Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1769"/>
        <description>WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T02:48:16">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:25.011-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:13.123-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:09.257-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:53.201-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:28.309-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:45.523-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:11.256-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7178 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:53.793-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:52.440-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:08.413-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:14.163-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:54.252-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:48.725-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.2.0.61" test_ref="oval:org.mitre.oval:tst:11571"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7176" version="5" class="vulnerability">
      <metadata>
        <title>Windows Kernel Malformed Image Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0482" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0482"/>
        <description>The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:30.424-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:46.708-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:32.698-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.290-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.290-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:48.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11261"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7170" version="12" class="vulnerability">
      <metadata>
        <title>VBScript Help Keypress Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>VBScript 5.1</product>
          <product>VBScript 5.6</product>
          <product>VBScript 5.7</product>
          <product>VBScript 5.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0483" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0483"/>
        <description>vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:44.231-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:45.682-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:31.660-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.494-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.494-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:47.385-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5645 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:11.887-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.175-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7170 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:06.347-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:25.228-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7170 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:35:00.796-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:37:48.734-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:01:09.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable VBScript 5.1 or VBScript 5.6 on Windows 2000, XP, Server 2003">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="VBScript 5.6 is installed" definition_ref="oval:org.mitre.oval:def:28988"/>
            <extend_definition comment="VBScript 5.1 is installed" definition_ref="oval:org.mitre.oval:def:28636"/>
          </criteria>
          <criterion comment="Vbscript.dll version is less than 5.6.0.8838" test_ref="oval:org.mitre.oval:tst:11472"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Windows 2000, XP, Server 2003">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is less than 5.7.6002.22354" test_ref="oval:org.mitre.oval:tst:11641"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.7.0.16000" test_ref="oval:org.mitre.oval:tst:11783"/>
          <criterion comment="Vbscript.dll version is less than 5.7.0.17033" test_ref="oval:org.mitre.oval:tst:11411"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.7.0.20000" test_ref="oval:org.mitre.oval:tst:11369"/>
          <criterion comment="Vbscript.dll version is less than 5.7.0.21238" test_ref="oval:org.mitre.oval:tst:11618"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.7.0.18000" test_ref="oval:org.mitre.oval:tst:11698"/>
          <criterion comment="Vbscript.dll version is less than 5.7.0.18440" test_ref="oval:org.mitre.oval:tst:11598"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.7.0.22000" test_ref="oval:org.mitre.oval:tst:11184"/>
          <criterion comment="Vbscript.dll version is less than 5.7.0.22648" test_ref="oval:org.mitre.oval:tst:11313"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.7.6002.18000" test_ref="oval:org.mitre.oval:tst:11133"/>
          <criterion comment="Vbscript.dll version is less than 5.7.6002.18222" test_ref="oval:org.mitre.oval:tst:11372"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.7 on Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.7.6002.22000" test_ref="oval:org.mitre.oval:tst:11703"/>
          <criterion comment="Vbscript.dll version is less than 5.7.6002.22354" test_ref="oval:org.mitre.oval:tst:11429"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.8 on Windows 2000, XP, Server 2003">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criterion comment="Vbscript.dll version is less than 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:11200"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.8 on All Microsoft Windows Vista x86/x64, Server 2008 32bit/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.8.6001.18000" test_ref="oval:org.mitre.oval:tst:11365"/>
          <criterion comment="Vbscript.dll version is less than 5.8.6001.18909" test_ref="oval:org.mitre.oval:tst:11382"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.8 on Microsoft Windows Vista x86/x64, Server 2008 SP2 32bit/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.8.6001.22000" test_ref="oval:org.mitre.oval:tst:11426"/>
          <criterion comment="Vbscript.dll version is less than 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:11200"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.8 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.8.7600.16000" test_ref="oval:org.mitre.oval:tst:11193"/>
          <criterion comment="Vbscript.dll version is less than 5.8.7600.16546" test_ref="oval:org.mitre.oval:tst:11713"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable VBScript 5.8 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criterion comment="Vbscript.dll version is greater than or equal 5.8.7600.20000" test_ref="oval:org.mitre.oval:tst:11059"/>
          <criterion comment="Vbscript.dll version is less than 5.8.7600.20662" test_ref="oval:org.mitre.oval:tst:11412"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7169" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows during YUV420 transformations</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
          <product>RealPlayer SP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0117"/>
        <description>RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows do not properly handle dimensions during YUV420 transformations, which might allow remote attackers to execute arbitrary code via crafted MP4 content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:24.934-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:12.757-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:08.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer SP is greater than or equal to 1.0" test_ref="oval:org.mitre.oval:tst:11442"/>
            <criterion comment="Check if the version of RealPlayer SP is less than 1.1.5" test_ref="oval:org.mitre.oval:tst:11165"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
            <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7167" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Invalid Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2168"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:20.871-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:30.842-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:13.835-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:05.514-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:20.961-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:29.493-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:09.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:11.335-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:46.689-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:48.398-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:46.131-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:57.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:05.281-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7166" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Heap Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2162"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors related to improper length calculation and the (1) STSC, (2) STSZ, and (3) STCO atoms.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:38.281-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:29.361-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:30.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:25.997-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:09.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:06.723-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7166 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:46.261-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:32.561-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:30.706-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:14.988-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:53.870-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.010-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7166 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:24.769-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7166 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:11.170-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:02.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7164" version="5" class="vulnerability">
      <metadata>
        <title>SMB Client Transaction Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0270"/>
        <description>The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:03.485-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:45.349-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:31.305-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.275-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.275-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:46.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7159" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4033"/>
        <description>Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:39.904-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:42.181-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:51.335-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:48.664-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:09.754-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:27.660-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:54.773-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:20:11.151-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:01.076-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:04:58.737-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:53.449-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:27:45.351-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:04.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7158" version="11" class="vulnerability">
      <metadata>
        <title>XML Signature HMAC Truncation Authentication Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217"/>
        <description>The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:33:22.713-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:28.102-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:29.682-04:00">ACCEPTED</status_change>
            <modified comment="Removed the Windows Server 2003 SP2 (x86) extended def reference in the larger .Net Framework 1.1 criteria section.  The proper test for .Net Framework 1.1 on 2003 x86 was already broken out separately." date="2010-07-28T13:32:00.593-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-07-28T13:33:31.800-04:00">INTERIM</status_change>
            <status_change date="2010-08-16T04:10:49.309-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.243-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.243-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:46.216-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7158 - Submitting updated MS10-041 bulletin. def:7158 - updated to include LDR support." date="2013-05-29T15:56:00.291-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-05-29T15:59:21.130-04:00">INTERIM</status_change>
            <status_change date="2013-06-17T04:00:30.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7158 - extended definitions of OS are without SP checks" date="2014-07-28T17:44:00.322-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:46:27.851-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:24.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 1.1 SP1">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of Mscorlib.dll is less than 1.1.4322.2463" test_ref="oval:org.mitre.oval:tst:27588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 1.1 Service Pack 1">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of System.Security.dll is less than 1.1.4322.2460" test_ref="oval:org.mitre.oval:tst:27732"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="System.web.dll version is less than 2.0.50727.1878" test_ref="oval:org.mitre.oval:tst:27523"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 or 3.5 SP1">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for Microsoft .NET Framework 2.0 Service Pack 2 or 3.5 SP1">
            <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
            <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          </criteria>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of System.Security.dll is less than 2.0.50727.3613" test_ref="oval:org.mitre.oval:tst:27623"/>
            <criteria operator="AND" comment="Check for LDR version">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:81021"/>
              <criterion comment="Check if System.Security.dll version is less than 2.0.50727.4434" test_ref="oval:org.mitre.oval:tst:81257"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="the version of System.Security.dll is less than 2.0.50727.1879" test_ref="oval:org.mitre.oval:tst:27098"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5 SP1 on Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of system.security.dll is less than 2.0.50727.4204" test_ref="oval:org.mitre.oval:tst:27451"/>
            <criteria operator="AND" comment="Check for LDR versions">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4300" test_ref="oval:org.mitre.oval:tst:80770"/>
              <criterion comment="Check if System.Security.dll version is less than 2.0.50727.4434" test_ref="oval:org.mitre.oval:tst:81257"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft .NET Framework 3.5.1 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of system.security.dll is less than 2.0.50727.4951" test_ref="oval:org.mitre.oval:tst:27053"/>
            <criteria operator="AND" comment="Check for LDR versions">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:org.mitre.oval:tst:80869"/>
              <criterion comment="Check if system.security.dll version is less than 2.0.50727.5007" test_ref="oval:org.mitre.oval:tst:81083"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7157" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTML Document Subtrees Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1761"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML document subtrees.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.118-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:12.536-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:29.443-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7157 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:17.540-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:09.155-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:42.748-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:09.007-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:19.715-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:49.575-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:58.364-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.457-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7154" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1290"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1291.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:47.885-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:33.082-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:15.751-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:08.350-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:33.842-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7151" version="14" class="vulnerability">
      <metadata>
        <title>Vulnerability in WebKit used in Google Chrome version less than 6.0.472.59 via vectors related to SVG styles</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1824"/>
        <description>Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-30T08:37:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:12.981-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:11.156-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:12.732-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:07.727-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:09.423-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:26.639-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:54.418-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:19:42.346-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:00.650-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:04:22.403-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:52.934-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:27:09.220-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:10:04.260-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7150" version="11" class="vulnerability">
      <metadata>
        <title>WebKit SVG 'use' Element Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1410"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an SVG document with nested use elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:49.784-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:12.323-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:29.239-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7150 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:10.056-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:08.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:35.912-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:08.617-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:09.852-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:48.656-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:56.504-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.369-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7149" version="11" class="vulnerability">
      <metadata>
        <title>IIS Authentication Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Information Server (IIS) 6.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1256"/>
        <description>Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:33:07.175-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:26.319-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:28.534-04:00">ACCEPTED</status_change>
            <modified comment="Updated the tests to account for EPA installation.  The file in the original tests, 'w3dt.dll', was not updated by MS10-040 on all platforms." date="2010-08-03T11:07:00.009-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-03T11:08:14.118-04:00">INTERIM</status_change>
            <status_change date="2010-08-23T04:00:34.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7149 - Modified to reflect MS10-040 better." date="2011-07-07T12:56:00.741-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-07-07T12:59:12.859-04:00">INTERIM</status_change>
            <status_change date="2011-07-25T04:00:10.676-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.119-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.119-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:45.331-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7149 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:14.536-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:32.258-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Windows Server 2003 x86/x64/ia64 SP2 - IIS 6.0">
          <criteria operator="OR" comment="Operating System Check for 2003 SP2 (x86, x64, ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="The version of W3dt.dll is less than 6.0.3790.4693" test_ref="oval:org.mitre.oval:tst:27546"/>
          <criterion comment="The version of W3dt.dll is greater than or equal to 6.0.3790.4667" test_ref="oval:org.mitre.oval:tst:40816"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1 - IIS 7.0 - GDR">
          <criteria operator="OR" comment="Operating System Check for Vista SP1 and server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Check">
            <criterion comment="The version of Iisw3adm.dll is less than 7.0.6001.18428" test_ref="oval:org.mitre.oval:tst:40772"/>
            <criteria operator="AND" comment="LDR Check">
              <criterion comment="The version of Iisw3adm.dll is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:40468"/>
              <criterion comment="The version of Iisw3adm.dll is less than 7.0.6001.22675" test_ref="oval:org.mitre.oval:tst:41210"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2 - IIS 7.0 - GDR">
          <criteria operator="OR" comment="Operating System Check for Vista SP2 and Server 2008 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Check">
            <criterion comment="The version of Iisw3adm.dll is less than 7.0.6002.18247" test_ref="oval:org.mitre.oval:tst:40216"/>
            <criteria operator="AND" comment="LDR Check">
              <criterion comment="The version of Iisw3adm.dll is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:40586"/>
              <criterion comment="The version of Iisw3adm.dll is less than 7.0.6002.22388" test_ref="oval:org.mitre.oval:tst:40780"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - IIS 7.5 - GDR">
          <criteria operator="OR" comment="Operating System Check for Windows 7 and Server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
          <criteria operator="OR" comment="GDR or LDR Check">
            <criterion comment="The version of Authsspi.dll is less than 7.5.7600.16576" test_ref="oval:org.mitre.oval:tst:27697"/>
            <criteria operator="AND" comment="LDR Check">
              <criterion comment="The version of Authsspi.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:27756"/>
              <criterion comment="The version of Authsspi.dll is less than 7.5.7600.20694" test_ref="oval:org.mitre.oval:tst:27782"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7145" version="11" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability (CVE-2010-0255)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0255"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:13.531-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:25.186-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:27.675-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:10.846-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:54.507-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:44.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.193-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.857-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7145 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:54.331-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:24.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7143" version="11" class="vulnerability">
      <metadata>
        <title>Apple Safari Window Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1750"/>
        <description>Use-after-free vulnerability in Apple Safari before 5.0 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper window management.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:45.680-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:12.113-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:27.385-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7143 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:14.632-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:08.437-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:37.168-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:08.251-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:11.684-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:46.585-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:56.731-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.276-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7140" version="14" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Unspecified Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3797"/>
        <description>Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:34.180-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:31.301-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:03.925-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:09.739-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:44.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:43.234-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:26.682-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:49.880-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:29.925-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:18.961-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:53.746-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:21.366-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7140 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:24.633-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7140 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:17.283-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:02.755-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7138" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3622"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:16.810-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:41.525-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:20.504-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:44.897-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:07.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:32.457-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:45.662-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:06.468-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:45.463-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:31.126-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:03.589-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.231-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:24.443-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7135" version="9" class="vulnerability">
      <metadata>
        <title>WebKit XML Document Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0048"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:39.211-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:44.227-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:30.426-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:38.150-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:07.417-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7135 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:30.784-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:52.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:12.914-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:44.840-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7134" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Director File Multiple Remote Code Execution Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0129" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0129"/>
        <description>Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:45.220-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:32.766-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:14.952-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.258-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:33.602-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7129" version="8" class="vulnerability">
      <metadata>
        <title>SMB Client Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0269"/>
        <description>The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:12.648-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:43.173-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:29.207-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:44.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:44.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:43.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:15.061-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:20.523-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Mrxsmb.sys version is less than 5.0.2195.7379" test_ref="oval:org.mitre.oval:tst:11414"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.3675" test_ref="oval:org.mitre.oval:tst:11126"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.5944" test_ref="oval:org.mitre.oval:tst:11710"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4671" test_ref="oval:org.mitre.oval:tst:11515"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.17025" test_ref="oval:org.mitre.oval:tst:11088"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21230" test_ref="oval:org.mitre.oval:tst:11469"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18431" test_ref="oval:org.mitre.oval:tst:11662"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22641" test_ref="oval:org.mitre.oval:tst:11205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18213" test_ref="oval:org.mitre.oval:tst:10963"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22346" test_ref="oval:org.mitre.oval:tst:11499"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7127" version="8" class="vulnerability">
      <metadata>
        <title>IIS Repeated Parameter Request Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Information Server (IIS) 5.1</product>
          <product>Microsoft Internet Information Server (IIS) 6.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1899"/>
        <description>Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:39:34.446-04:00">DRAFT</status_change>
            <modified comment="Added new check for asp.dll on IIS 5.1/Win XP SP3 and corrected object obj:4885 to identify asp51.dll under system32\dllcache directory." date="2010-09-22T21:20:00.563-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-10-11T04:00:11.366-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:07.355-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:45.821-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.821-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:42.466-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7127 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.727-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable IIS 5.1 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criteria operator="OR" comment="file version">
            <criterion comment="the version of asp51.dll is less than 5.1.2600.6007" test_ref="oval:org.mitre.oval:tst:11663"/>
            <criterion comment="the version of asp.dll is less than 5.1.2600.6007" test_ref="oval:org.mitre.oval:tst:11082"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 6.0 on Windows XP x64, Windows Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="The version of asp.dll is less than 6.0.3790.4735" test_ref="oval:org.mitre.oval:tst:11245"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.0 on Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of asp.dll is less than 7.0.6001.18497" test_ref="oval:org.mitre.oval:tst:11366"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of asp.dll is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11214"/>
              <criterion comment="The version of asp.dll is less than 7.0.6001.22718" test_ref="oval:org.mitre.oval:tst:11379"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.0 on Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of asp.dll is less than 7.0.6002.18276" test_ref="oval:org.mitre.oval:tst:11539"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of asp.dll is greater than or equal 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11514"/>
              <criterion comment="The version of asp.dll is less than 7.0.6002.22431" test_ref="oval:org.mitre.oval:tst:11664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.5 on Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of asp.dll is less than 7.5.7600.16620" test_ref="oval:org.mitre.oval:tst:11219"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of asp.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:11656"/>
              <criterion comment="The version of asp.dll is less than 7.5.7600.20741" test_ref="oval:org.mitre.oval:tst:11498"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:460" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 5.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 5.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:5.1"/>
        <description>The application Microsoft IIS 5.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:27.089-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.067-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.815-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:14:32.837-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:46.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:460 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.071-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS 5.1 Minor Version" test_ref="oval:org.mitre.oval:tst:1357"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:227" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:6.0"/>
        <description>The application Microsoft IIS 6.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:16.652-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.614-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.336-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:13:22.361-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:39.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:227 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.941-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:14.871-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 6" test_ref="oval:org.mitre.oval:tst:170"/>
        <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7126" version="21" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player URL Parsing Vulnerability that could lead to cross-site scripting (Firefox and Chrome browsers only)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
          <product>Google Chrome</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2179"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when Firefox or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to URL parsing.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:42.346-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:23.889-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:27.069-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:31.328-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:07.973-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:13.437-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7126 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:45.224-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7126 - Adds criterion for missing browser portion" date="2013-06-04T14:44:00.077-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-06-04T14:46:32.805-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:28.863-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:21.423-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:53.608-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:08.207-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7126 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:24.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7126 - Modified Firefox vulnerabilities (def:6562 replaced by def:22259)" date="2015-07-15T15:01:00.143-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-15T15:03:14.392-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7126 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:35:00.796-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-10T04:01:08.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Chrome or Firefox installed">
          <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
          <extend_definition comment="Mozilla Firefox is installed" definition_ref="oval:org.mitre.oval:def:6562"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of AIR or Flash Player installed">
          <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
            <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
            <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
            <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
              <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
            </criteria>
            <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
              <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6562" version="12" class="inventory">
      <metadata>
        <title>Mozilla Firefox is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference ref_id="cpe:/a:mozilla:firefox" source="CPE"/>
        <description>The browser installed on the system is Mozilla Firefox</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:20.733-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:20.248-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:16.346-05:00">ACCEPTED</status_change>
            <modified comment="Removed individual OS tests" date="2010-01-07T13:23:00.987-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-07T13:24:45.994-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:24.871-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5310 - Update to oval:org.mitre.oval:ste:5310 to deal with version 10 and above." date="2012-02-21T14:57:00.905-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2012-02-21T14:59:35.582-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.775-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:16.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:18.660-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:47.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6562 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:06:12.774-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:00.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6562 - inventory for Mozilla ESR and Mainline products" date="2014-02-07T11:52:00.460-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-07T11:55:12.847-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.154-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Mozilla Firefox is installed" test_ref="oval:org.mitre.oval:tst:11127"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7125" version="8" class="vulnerability">
      <metadata>
        <title>Heap Based Buffer Overflow in Outlook Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Outlook 2002</product>
          <product>Microsoft Outlook 2003</product>
          <product>Microsoft Outlook 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2728" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2728"/>
        <description>Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-13T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-09-16T11:39:20.970-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:40.394-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:23.756-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:240 - Updated objects to reflect proper version of office outlook (was 2K, should be 2002 &amp; 2003)" date="2011-07-14T13:06:00.227-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-14T13:07:00.539-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11568 - Updated objects to reflect proper version of office outlook (was 2K, should be 2002 &amp; 2003)" date="2011-07-14T13:06:00.392-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-08-01T04:00:58.513-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:247 - Updating pre-Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:55:00.075-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:56:56.273-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:23.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Outlook 2002">
          <extend_definition comment="Microsoft Outlook 2002 is installed" definition_ref="oval:org.mitre.oval:def:5179"/>
          <criterion comment="the version of Msmapi32.dll is less than 5.5.3203.0" test_ref="oval:org.mitre.oval:tst:11278"/>
        </criteria>
        <criteria operator="AND" comment="Outlook 2003">
          <extend_definition comment="Microsoft Outlook 2003 is installed" definition_ref="oval:org.mitre.oval:def:5505"/>
          <criterion comment="the version of Msmapi32.dll is less than 11.0.8323.0" test_ref="oval:org.mitre.oval:tst:11568"/>
        </criteria>
        <criteria operator="AND" comment="Outlook 2007">
          <extend_definition comment="Microsoft Outlook 2007 is installed" definition_ref="oval:org.mitre.oval:def:5352"/>
          <criterion comment="the version of Outlook.exe is less than 12.0.6539.5000" test_ref="oval:org.mitre.oval:tst:11155"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7124" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-1261)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1261"/>
        <description>The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:18.985-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:23.322-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:26.457-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:12.401-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:53.783-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:45.525-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.525-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:41.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7124 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.328-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7122" version="8" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Microsoft Visio 2003</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Visio 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3148"/>
        <description>Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T04:21:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:23.663-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:40.690-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:50.428-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7122 - Replaced test oval:org.mitre.oval:tst:20473 (Check if the version of Microsoft Visio 2003 installed is equal to 11.0.3216.5614) with a new test that checks if OMFCU.DLL version is less than 11.0.8332.0" date="2011-07-14T13:02:00.687-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-07-14T13:03:08.726-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:58.191-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15896 - Updates to Visio related definitions to fix Object collection concerns." date="2013-01-22T15:55:00.810-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-22T16:11:06.575-05:00">INTERIM</status_change>
            <status_change date="2013-02-11T04:03:45.086-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office Visio 2003 is installed" definition_ref="oval:org.mitre.oval:def:1450"/>
        <criterion comment="OMFCU.DLL version is less than 11.0.8332.0" test_ref="oval:org.mitre.oval:tst:43583"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7121" version="5" class="vulnerability">
      <metadata>
        <title>Word Uninitialized Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2747" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2747"/>
        <description>Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:30.575-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:12.455-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:21.703-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:38.758-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:23.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7118" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2186"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:44.164-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:22.935-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:26.022-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:28.676-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:07.593-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:10.148-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7118 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:44.707-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:36.184-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:27.979-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.658-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:53.470-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.232-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7118 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:24.120-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7118 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:08.719-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:02.538-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7116" version="30" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1297"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-07T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:38.600-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:11.412-04:00">INTERIM</status_change>
            <modified comment="Updated the criteria to include relevant products and versions." date="2010-07-02T09:51:00.122-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-07-19T04:00:25.499-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:05.433-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:19.925-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:28.387-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:06.741-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27694 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:20.904-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7116 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:43.960-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:47.282-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:43.803-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:31.817-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:26.356-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:55.534-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:02.713-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:14.814-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:53.211-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7381 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:28.274-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7116 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:23.845-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7116 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:06.413-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:02.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7110" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes Install or Update Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0532" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0532"/>
        <description>Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:38.335-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:42.459-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:28.224-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:53.533-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:27.926-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:45.883-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:10.903-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7110 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:49.896-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:51.689-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:30.464-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:13.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:59.718-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:48.441-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7108" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0130" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0130"/>
        <description>Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:45.423-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:32.502-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:14.474-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:08.729-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:33.303-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7106" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0198"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0199, CVE-2010-0202, and CVE-2010-0203.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:38.944-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:42.072-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:27.766-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.341-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:19.429-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:40.384-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:06.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:24.791-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:43.393-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:59.901-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:42.987-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:22.274-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:01.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7099" version="11" class="vulnerability">
      <metadata>
        <title>WebKit IBM1147 Character Set Text Transform Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1770"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.557-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:11.188-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:25.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7099 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:16.867-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:07.257-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:40.900-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:05.567-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:16.861-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:42.824-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.775-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.172-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7096" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2177"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:41.768-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:21.138-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:24.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:27.689-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:06.810-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:08.880-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7096 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:42.899-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:54.908-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:25.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:20.581-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:53.084-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.759-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7096 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:23.602-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7096 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:12.967-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:01.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7082" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Path Traversal Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1391"/>
        <description>Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to create arbitrary database files via vectors involving a (1) %2f and .. (dot dot) or (2) %5c and .. (dot dot) in a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:46.262-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:10.899-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:24.669-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7082 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:12.277-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:06.477-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:32.074-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:05.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:04.693-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:40.849-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:54.752-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:04.045-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7077" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 Sorenson Encoded Movie Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0518" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0518"/>
        <description>QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:56.577-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:41.294-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:26.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:09.456-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:04.849-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:36.253-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:26.290-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7077 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:15.113-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:51.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7074" version="5" class="vulnerability">
      <metadata>
        <title>VBE6.DLL Stack Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office 2000</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office 2007</product>
          <product>Microsoft Visual Basic for Applications</product>
        </affected>
        <reference ref_id="CVE-2010-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0815" source="CVE"/>
        <description>VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-05-12T12:23:28.732-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:32.140-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:13.110-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7074 - New inventory added Microsoft Office 2007 SP1 is installed and test  tst:79757 was changed" date="2014-05-08T11:08:00.572-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-08T11:09:44.034-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:29.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Office XP/2003 SP3/2007 SP2/2007 SP1/Visual Basic 6.0">
          <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Office 2003 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15626"/>
          <extend_definition comment="Microsoft Office 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15607"/>
          <extend_definition comment="Microsoft Office 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:23724"/>
          <extend_definition comment="Microsoft Visual Basic for Applications is installed" definition_ref="oval:org.mitre.oval:def:1746"/>
        </criteria>
        <criterion comment="the version of Vbe6.dll is less than 6.5.10.53" test_ref="oval:org.mitre.oval:tst:11504"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7072" version="5" class="vulnerability">
      <metadata>
        <title>OpenType CFF Font Driver Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0819"/>
        <description>Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:45.172-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:19.758-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:24.036-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.165-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.165-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:40.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Atmfd.dll is less than 5.0.2.227" test_ref="oval:org.mitre.oval:tst:27043"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2/SP3">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.2.2.228" test_ref="oval:org.mitre.oval:tst:26783"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7071" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'ConditionEventListener' Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1402"/>
        <description>Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to an event listener in an SVG document, related to duplicate event listeners, a timer, and an AnimateTransform object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:48.457-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:10.677-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:23.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7071 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:07.237-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:06.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:30.482-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:04.143-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:02.324-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:39.265-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:53.657-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.950-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7070" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Uninitialized Memory Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2205"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, access uninitialized memory, which allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:22.350-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:23.364-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:13.365-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:05.815-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:18.829-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:30.545-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:03.575-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:12.111-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:42.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:48.945-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:42.386-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:59.278-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:01.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7064" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0196"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:38.249-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:40.084-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:25.585-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:10.522-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:18.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:53.107-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:02.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:59.977-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:41.676-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:38.115-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:41.743-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:46.795-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:10:00.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7062" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 RLE Encoded Movie Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0516"/>
        <description>Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding, which triggers memory corruption when the length of decompressed data exceeds that of the allocated heap chunk.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:56.883-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:39.841-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:25.371-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:10.314-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:02.725-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:47.303-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:25.744-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7062 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:03.269-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:50.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7061" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes JavaScriptCore Page Transitions Denial Of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1387"/>
        <description>Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T02:48:16">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:25.307-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:10.954-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:06.814-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:52.840-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:27.520-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:45.168-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:10.472-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7061 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:45.877-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:50.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7061 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:51:18.899-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:13.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:51.596-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:48.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.2.0.61" test_ref="oval:org.mitre.oval:tst:11571"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7059" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-3328)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3328" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3328"/>
        <description>Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:22.389-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:11.414-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:20.058-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.978-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.978-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:38.409-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.435-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.025-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7059 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:52.726-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.032-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7057" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3632"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, and CVE-2010-3658.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:19.708-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:39.304-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:17.827-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:50.595-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:02.257-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:58.439-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:40.588-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:35.074-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:41.116-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:41.973-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:59.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:14.184-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:23.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7056" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0201"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:39.696-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:39.393-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:24.907-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:10.144-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:17.323-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:52.127-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:01.674-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:58.956-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:39.921-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:37.497-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:40.446-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:45.505-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:59.135-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7053" version="9" class="vulnerability">
      <metadata>
        <title>WebKit CSS 'format()' Arguments Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0046"/>
        <description>The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:38.833-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:39.186-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:24.692-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:22.403-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:01.409-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7053 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:22.827-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:49.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:50.573-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:38.124-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7052" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0987"/>
        <description>Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:45.819-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:31.823-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:12.603-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.104-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:33.085-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7051" version="9" class="vulnerability">
      <metadata>
        <title>Apple Safari Prior to 4.0.5 Configuration Bypass Weakness</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0044"/>
        <description>PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:38.509-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:38.934-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:24.482-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:22.181-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:01.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7051 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:28.300-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:49.586-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:50.205-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:37.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7049" version="17" class="vulnerability">
      <metadata>
        <title>LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple Safari</product>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2285"/>
        <description>Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:37.359-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:38.706-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:24.224-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:51.266-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:27.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:21.244-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:00.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:43.402-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:10.063-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7049 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:32.376-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:49.110-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:52:51.196-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:12.564-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:48.585-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:34.999-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:49.615-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:47.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check iTunes">
          <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
          <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
        </criteria>
        <criteria operator="AND" comment="Check Safari">
          <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
          <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7046" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0192"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0193 and CVE-2010-0196.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:36.594-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:38.277-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:23.760-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.138-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:16.796-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:43.650-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:00.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:48.517-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:39.332-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:26.589-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:39.771-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:28.868-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:58.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7043" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 H.261 Encoded Movie Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0514"/>
        <description>Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.261 encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:57.256-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:38.072-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:23.538-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:04.994-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:59.962-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:42.055-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:25.293-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7043 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:12.837-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:48.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7042" version="6" class="vulnerability">
      <metadata>
        <title>Excel Record Parsing Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3230" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3230"/>
        <description>Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:38.173-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:31:00.031-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:10.225-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:14.824-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:57.593-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:22.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7041" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'removeChild' DOM Method Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1414"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the removeChild DOM method.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:50.294-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:10.456-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:22.865-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7041 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:18.105-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:05.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:16.582-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:59.608-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:42.453-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:33.774-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:54.526-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.838-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7037" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'removeChild()' Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1119"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:46.918-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:10.234-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:22.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7037 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:11.700-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:05.274-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:16.264-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:59.243-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:42.069-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:32.843-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:54.433-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.750-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7034" version="13" class="vulnerability">
      <metadata>
        <title>Problem in handling fonts in Google Chrome version less than 4.1.249.1064</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1665" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1665"/>
        <description>Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-13T19:43:23">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:34:42.344-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:39.396-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:22.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11639 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:12.758-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:09.118-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:22.008-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:54.017-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:18:23.077-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:08:00.257-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:02:30.559-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:52.438-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:25:17.819-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:57.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check version installed is less than 4.1.249.1064" test_ref="oval:org.mitre.oval:tst:11639"/>
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7032" version="9" class="vulnerability">
      <metadata>
        <title>Word Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
          <product>Microsoft Word 2003</product>
          <product>Microsoft Office Word Viewer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3221" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3221"/>
        <description>Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:35.121-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:10.859-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:19.618-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1517 - In obj:1517 for Office Word Viewer is updated by adding new variable and object to make it work. Earlier obj:1517 was referring to OfficeWord object path" date="2011-07-18T15:27:00.494-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-18T15:28:20.635-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:53.315-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6394 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:17.118-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:21.786-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15263 - added new criteria and 32 bit checks." date="2013-01-31T09:01:00.731-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-31T09:03:28.989-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:32.815-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2002">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
        </criteria>
        <criteria operator="AND" comment="Word 2003">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of Winword.exe is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11358"/>
        </criteria>
        <criteria operator="AND" comment="Word Viewer">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of Wordview.exe is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11354"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7031" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Caption Element Handling Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1400" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1400"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving caption elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:48.129-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:09.676-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:22.418-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7031 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:19.270-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:04.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:11.315-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:58.816-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:34.891-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:31.463-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:53.351-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.665-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7030" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird, Seamonkey and Firefox Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1302"/>
        <description>The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:06:34.229-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:24.056-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:13.946-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:33:58.318-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:57.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:59:41.998-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:07.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7030 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:59.516-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.784-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7030 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:38.242-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:32.072-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:26:57.633-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7030 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:23.496-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:13:52.657-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:22.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:43.670-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:23.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7028" version="6" class="vulnerability">
      <metadata>
        <title>Formula Biff Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3235" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3235"/>
        <description>Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:43.240-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:33:00.641-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:09.830-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:14.438-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:55.100-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:20.973-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7024" version="11" class="vulnerability">
      <metadata>
        <title>WebKit HTML Button Use After Free Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1392" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1392"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to HTML buttons and the first-letter CSS style.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:46.430-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:09.453-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:22.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7024 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:22.639-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:04.516-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:10.005-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:58.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:33.310-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:30.611-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:52.321-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.573-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7019" version="6" class="vulnerability">
      <metadata>
        <title>Word Index Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3219" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3219"/>
        <description>Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:34.651-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:25:00.270-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:09.410-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:13.874-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:36.266-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:20.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7014" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2180"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:42.598-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:16.953-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:21.807-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:28.007-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:04.129-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:09.294-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7014 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:38.844-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:35.682-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:24.495-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.579-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:52.943-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.916-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7014 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:23.016-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7014 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:13.206-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:01.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7011" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR NULL Pointer Exception Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1865" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1865"/>
        <description>Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a "null pointer vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:31.868-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:30.900-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:43:00.303-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:09.957-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:49.755-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:24.737-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:33.570-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:23.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.191-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:25.465-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7011 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-19T15:03:00.511-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:22.858-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7011 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:08.201-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:01.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123306"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:123732"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7010" version="6" class="vulnerability">
      <metadata>
        <title>Word Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3218" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3218"/>
        <description>Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:34.445-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:26:00.281-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:08.985-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:13.426-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:37.215-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:19.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7009" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Font Parsing Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2889" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2889"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-3626.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:14.901-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:37.633-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:16.332-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:37.414-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:57.895-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:21.463-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:38.299-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:55.865-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:39.167-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:16.242-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:57.242-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:14.904-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:22.695-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7008" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird, Firefox and Seamonkey arbitrary code execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307"/>
        <description>The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:08:20.130-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:23.286-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:13.269-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:54.166-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:57.215-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:29.432-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:06.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7008 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:08.506-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.650-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7008 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:39.126-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:31.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:43.795-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7008 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:23.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:41.820-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:22.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:39.918-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:22.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7007" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Code Execution via crafted image Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3629"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3620.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:18.886-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:37.206-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:15.792-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:37.853-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:57.378-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:22.544-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:37.656-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:57.451-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:38.512-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:16.830-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:56.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.089-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:22.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7006" version="3" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in Free Download Manager (FDM).</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Free Download Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0998" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0998"/>
        <description>Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-20T03:34:03">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2010-05-21T09:03:25.644-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:21.981-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:09.147-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Free Download Manager">
          <extend_definition comment="Free Download Manager is installed" definition_ref="oval:org.mitre.oval:def:6797"/>
          <criterion comment="Free Download Manager binary version is less than 3.0.852.0" test_ref="oval:org.mitre.oval:tst:11305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6797" version="5" class="inventory">
      <metadata>
        <title>Free Download Manager is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Free Download Manager</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:freedownloadmanager:free_download_manager"/>
        <description>Free Download Manager is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-20T03:34:03">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2010-05-21T09:03:25.343-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:11.588-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:06.250-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6797 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:37.651-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:40.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Free Download Manager is installed" test_ref="oval:org.mitre.oval:tst:11300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7005" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'Node.normalize' Method Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1759" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1759"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:51.909-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:08.871-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:21.584-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7005 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:04.902-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:03.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:32.392-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:56.960-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:05.194-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:29.969-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.163-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.420-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6999" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2171" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2171"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors related to SWF files, decompression of embedded JPEG image data, and the DefineBits and other unspecified tags, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:40.429-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:15.902-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:21.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:25.349-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:03.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:05.917-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6999 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:37.217-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:28.567-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:22.675-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:14.149-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:52.672-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:05.710-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6999 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:22.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6999 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:15.510-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:00.813-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6998" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR 'intf_count' Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1869"/>
        <description>Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:32.948-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:30.569-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:43:00.964-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:09.590-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:50.584-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:24.269-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:27.737-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:22.159-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.984-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:25.309-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6998 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-19T15:03:01.482-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:21.974-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6998 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:12.043-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:00.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123306"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:123732"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6991" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2189"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when used in conjunction with VMWare Tools on a VMWare platform, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:45.475-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:14.738-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:20.821-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:24.332-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:03.097-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:04.166-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6991 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:36.695-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:25.354-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:21.271-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.568-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:52.363-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:05.332-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6991 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:21.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6991 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:08.951-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:00.325-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMWare Tools is installed" definition_ref="oval:org.mitre.oval:def:7249"/>
        <criteria operator="OR" comment="Vulnerable version of Adobe AIR or Flash Player installed">
          <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
            <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
            <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
            <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
              <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
            </criteria>
            <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
              <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7249" version="7" class="inventory">
      <metadata>
        <title>VMWare Tools is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>VMWare Tools</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:vmware:tools"/>
        <description>VMWare Tools is installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:45.281-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:33.949-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:35.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7249 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:39.490-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:40.957-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7249 - modified inventories for Microsoft Expression Design." date="2013-07-05T09:53:00.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:58:06.604-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:12.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMWare Tools is installed" test_ref="oval:org.mitre.oval:tst:27703"/>
        <criterion comment="Registry that holds the location of where VMWare Tools exists" test_ref="oval:org.mitre.oval:tst:81440"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6989" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 Color Tables Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0528"/>
        <description>Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:55.315-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:36.556-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:21.555-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:10.093-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:56.695-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:46.619-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:23.799-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6989 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:30.043-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:48.288-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6988" version="13" class="vulnerability">
      <metadata>
        <title>Apple iTunes Crafted itpc: URL Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1777"/>
        <description>Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T02:48:16">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:24.698-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:10.632-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:06.440-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:50.912-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:26.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:43.006-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:09.447-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6988 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:51.458-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:47.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:44.301-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:12.097-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:54:03.278-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:47.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.2.1.4" test_ref="oval:org.mitre.oval:tst:11026"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6986" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0190"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:35.830-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:36.135-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:21.146-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:09.708-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:15.299-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:50.090-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:56.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:37.536-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:36.125-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:11.268-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:37.845-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:41.355-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:55.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6981" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'first-letter' CSS Style Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1401"/>
        <description>Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the :first-letter pseudo-element.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:48.291-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:08.644-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:20.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6981 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:10.595-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:02.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:40.576-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:55.762-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:16.459-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:28.736-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.700-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6976" version="15" class="vulnerability">
      <metadata>
        <title>Vulnerability in Adobe Reader 8.x and 9.x on Windows - to execute EXE files embedded in a PDF document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4764"/>
        <description>Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-18T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-18T17:07:55.922-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:20.734-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:08.268-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.683-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:14.871-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:479 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:40:21.824-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:55.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:28.948-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:35.601-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:03.469-05:00">INTERIM</status_change>
            <status_change date="2013-02-11T04:03:37.277-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T11:02:12.785-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:54.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal 8.1.7" test_ref="oval:org.mitre.oval:tst:11276"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.1.7" test_ref="oval:org.mitre.oval:tst:11095"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20886"/>
            <criterion comment="Adobe Reader library is less than 9.3.1" test_ref="oval:org.mitre.oval:tst:20828"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6975" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey Chrome Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0178" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0178"/>
        <description>Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:03.094-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:35.753-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:20.409-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:02.009-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:56.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:37.712-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:06.501-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6975 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:55:03.113-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.518-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6975 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:34.557-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:17.714-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.512-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:21.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.0.19" test_ref="oval:org.mitre.oval:tst:120957"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6974" version="6" class="vulnerability">
      <metadata>
        <title>Word Return Value Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3215" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3215"/>
        <description>Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:33.798-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:26:00.686-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:08.574-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:12.670-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:35.185-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:18.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6972" version="14" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Multiple Unspecified Remote Code Execution Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3800"/>
        <description>Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:34.889-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:30.264-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:03.591-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:09.820-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:35.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:41.608-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:22.841-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:47.794-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:20.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:18.336-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:52.248-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:20.955-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6972 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:21.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6972 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:09.478-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:00.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:123200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6971" version="15" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey Arbitrary Code Execution With Firebug XMLHttpRequestSpy Module Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0179"/>
        <description>Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:03.499-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:35.065-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:20.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:01.270-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:56.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:36.848-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:06.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6971 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:47.469-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.378-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6971 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:36.175-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:17.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:24.430-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:21.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is before 3.0.19" test_ref="oval:org.mitre.oval:tst:120962"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.8" test_ref="oval:org.mitre.oval:tst:120828"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:99813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6969" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 BMP Image Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0536"/>
        <description>Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:55.588-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:34.826-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:19.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:06.663-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:54.869-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:31.460-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:22.400-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6969 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:42.532-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:47.332-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6967" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0986"/>
        <description>Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:45.628-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:31.527-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:11.125-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:06.333-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:32.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6961" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1863"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a "privilege escalation vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:30.941-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:29.909-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:43:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:09.219-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:50.987-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:21.808-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:47.800-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:20.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:06.612-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:25.070-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6961 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-19T15:03:00.984-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:21.055-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6961 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:15.713-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:59.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123306"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:123732"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6957" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2209"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:23.823-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:20.130-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:12.851-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.938-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:14.381-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:38.333-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:54.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:41.670-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:34.978-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:19.919-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:36.605-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:18.232-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:54.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6956" version="11" class="vulnerability">
      <metadata>
        <title>MHTML Mime-Formatted Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0096" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0096"/>
        <description>The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-01-31T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-01-31T17:59:59.792-05:00">DRAFT</status_change>
            <status_change date="2011-02-21T04:01:12.881-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:02.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6956 - New Definitions for April 2011 Patch Tuesday" date="2011-04-18T00:15:00.288-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-18T00:16:04.297-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:41.506-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.415-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.415-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:37.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12418 - Patch Tuesday - 7/2012 - also added comment to state." date="2012-07-13T11:28:00.032-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-07-13T11:34:02.798-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:35.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.6090" test_ref="oval:org.mitre.oval:tst:41714"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows XP SP2 x64, Server 2003 SP2 x86/x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows XP SP2 x64, Server 2003 SP2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.4841" test_ref="oval:org.mitre.oval:tst:42540"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18612" test_ref="oval:org.mitre.oval:tst:42392"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22867" test_ref="oval:org.mitre.oval:tst:42501"/>
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18417" test_ref="oval:org.mitre.oval:tst:42538"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
              <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22601" test_ref="oval:org.mitre.oval:tst:42194"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.16776" test_ref="oval:org.mitre.oval:tst:42627"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11895"/>
              <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.20918" test_ref="oval:org.mitre.oval:tst:42493"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64 SP1, Windows Server 2008 R2 x64 SP1">
          <criteria operator="OR" comment="Vulnerable Microsoft Windows 7 x86/x64 SP1, Windows Server 2008 R2 x64 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Inetcomm.dll is less than 6.1.7601.17574" test_ref="oval:org.mitre.oval:tst:42001"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42490"/>
              <criterion comment="the version of Inetcomm.dll is less than 6.1.7601.21677" test_ref="oval:org.mitre.oval:tst:42660"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6948" version="9" class="vulnerability">
      <metadata>
        <title>Win32k Window Creation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0485" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0485"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:24.406-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:11.734-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:19.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6948 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:59:00.878-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T16:00:04.782-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:12.131-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.994-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.994-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:36.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:00.911-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:19.764-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16585" test_ref="oval:org.mitre.oval:tst:27474"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20704" test_ref="oval:org.mitre.oval:tst:27593"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6946" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2188"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:44.645-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:11.412-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:18.758-04:00">ACCEPTED</status_change>
            <modified comment="Fixed upper bounds for Adobe definition." date="2010-08-12T12:56:00.451-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-12T12:58:37.526-04:00">INTERIM</status_change>
            <status_change date="2010-08-30T04:00:13.146-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41279 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:26:36.563-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6946 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:34.532-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:02.969-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:19.509-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:09.457-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:51.975-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7381 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:28.121-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6946 - checks the version of Flash .ocx" date="2014-09-19T15:01:00.953-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-06T04:04:20.817-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6946 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:05.417-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:59.666-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 2.0.3" test_ref="oval:org.mitre.oval:tst:41289"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:123372"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:123434"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:123741"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:123701"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6945" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey gczeal (vector) Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774"/>
        <description>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:04:34.330-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:22.827-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:12.862-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:43.195-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:01.622-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:19.084-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:55.701-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:01.901-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:05.556-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6945 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:55:00.648-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.231-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6945 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:40.231-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:31.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:01.786-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6945 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:23.085-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:13:57.412-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:22.273-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:48.989-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:20.419-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6940" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Heap-based Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1241"/>
        <description>Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:41.189-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:34.188-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:19.241-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:08.665-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:13.580-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:46.448-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:53.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:51.527-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:33.831-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:29.118-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:35.930-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:33.876-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:53.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6937" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome Pop-up Blocking Functionality Unspecified DoS</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3413" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3413"/>
        <description>Unspecified vulnerability in the pop-up blocking functionality in Google Chrome before 6.0.472.59 allows remote attackers to cause a denial of service (application crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:03.970-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:10.349-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:06.087-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:05.143-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:08.745-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:24.649-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:53.650-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:18:54.229-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:59.823-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:03:13.864-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:51.951-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:26:00.258-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:53.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6933" version="7" class="vulnerability">
      <metadata>
        <title>Request Header Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Information Server (IIS) 7.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2730"/>
        <description>Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-09-16T11:39:35.310-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:38.851-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:21.682-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.619-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.619-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:36.375-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6933 - The attached file contains modified vulnerability def:6933. The new test was added." date="2013-07-11T13:22:00.246-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-11T13:28:18.744-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:46.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Vulnerable OS 7\2008 r2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criterion negate="true" comment="The version of cgi.dll is equal to 7.5.7600.16385" test_ref="oval:org.mitre.oval:tst:81632"/>
        <extend_definition comment="Microsoft IIS 7.5 is installed" definition_ref="oval:org.mitre.oval:def:6856"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="The version of cgi.dll is less than 7.5.7600.16632" test_ref="oval:org.mitre.oval:tst:11599"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="The version of cgi.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:11765"/>
            <criterion comment="The version of cgi.dll is less than 7.5.7600.20752" test_ref="oval:org.mitre.oval:tst:11459"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6931" version="7" class="vulnerability">
      <metadata>
        <title>Apache 'mod_proxy_http' Timeout Detection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2068"/>
        <description>mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-14T12:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T16:45:34.264-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:11.145-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:18.444-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:707 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:28:05.208-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:53.166-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12088 - The check of 32-bit registry branche was added." date="2014-06-25T16:23:00.620-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-25T16:25:01.137-04:00">INTERIM</status_change>
            <status_change date="2014-07-14T04:01:26.478-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache HTTP Server 2.2.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8550"/>
        <criterion comment="The version of libhttpd.dll is less than or equal to 2.2.15" test_ref="oval:org.mitre.oval:tst:27432"/>
        <criterion comment="The version of libhttpd.dll is greater than or equal to 2.2.9" test_ref="oval:org.mitre.oval:tst:27557"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6930" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2211"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2212.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:24.597-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:17.945-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:12.401-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:11.411-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:13.088-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:55.686-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:52.645-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:02.885-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:33.260-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:40.770-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:35.287-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:50.364-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:52.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6929" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2210"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:24.233-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:17.495-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:11.891-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:05.024-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:12.572-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:26.307-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:52.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:07.947-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:32.168-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:45.612-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:34.614-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:51.313-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:51.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6928" version="9" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3330" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3330"/>
        <description>Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:23.959-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:09.675-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:18.717-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:35.465-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:58.366-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:19.499-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6928 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:56.837-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:22.032-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6927" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 MPEG Encoded Movie Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0526"/>
        <description>Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPEG encoding, which is not properly handled during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:56.100-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:33.932-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:18.995-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:03.468-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:51.861-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:28.164-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:21.397-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6927 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:05.336-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:46.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6926" version="17" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Adobe Flash Player version less than 9.0.289.0 and 10.x before 10.1.102.64</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3976" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3976"/>
        <description>Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:28:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:36.842-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:36.639-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.001-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6926 - Updated definition to match for 9.0.289.0 and 10.x before 10.1.192.64." date="2011-03-22T13:20:00.183-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-03-22T13:25:18.600-04:00">INTERIM</status_change>
            <status_change date="2011-04-11T04:00:15.757-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - New Adobe Flash 11 inventory definition and updated obj:7290's name element to do equals instead of an unnecessary pattern match." date="2011-10-11T14:22:00.150-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-11T14:23:14.446-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:16.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:37.806-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:19.003-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.962-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:51.843-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41644 - check=&quot;all&quot; was replased with check=&quot;at least one&quot; because all objects have the set of objects." date="2014-03-21T13:14:00.094-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-21T13:17:05.507-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:56.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6926 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:26.334-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:20.229-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6926 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:14.957-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:59.454-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check if Adobe Flash Player version is less than 9.0.289.0">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Check if Adobe Flash Player version less than 9.0.289.0" test_ref="oval:org.mitre.oval:tst:41644"/>
        </criteria>
        <criteria operator="AND" comment="Check if Adobe Flash Player version is 10.x before 10.1.102.64">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Check if Adobe Flash Player version less than 10.1.102.64" test_ref="oval:org.mitre.oval:tst:41260"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 10.1.102.64" test_ref="oval:org.mitre.oval:tst:123044"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.289.0" test_ref="oval:org.mitre.oval:tst:123109"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6922" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 QDM2 Encoded Audio Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0059"/>
        <description>CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:57.724-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:33.723-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:18.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:07.426-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:51.603-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:33.412-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:20.965-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6922 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:23.714-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:45.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6921" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey DoS and Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305"/>
        <description>The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:07:33.118-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:21.847-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:12.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:34.937-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:55.256-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:18.533-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:05.111-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6921 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:55:04.714-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:50.072-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6921 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:37.592-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:31.538-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:06.562-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6921 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:22.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:02.183-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:21.822-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:55.274-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:19.830-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6918" version="8" class="vulnerability">
      <metadata>
        <title>SMB Client Response Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0476"/>
        <description>The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:13.397-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:32.979-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:18.022-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.915-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.915-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:34.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.918-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:19.180-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4671" test_ref="oval:org.mitre.oval:tst:11515"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.17025" test_ref="oval:org.mitre.oval:tst:11088"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21230" test_ref="oval:org.mitre.oval:tst:11469"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18431" test_ref="oval:org.mitre.oval:tst:11662"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22641" test_ref="oval:org.mitre.oval:tst:11205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18213" test_ref="oval:org.mitre.oval:tst:10963"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22346" test_ref="oval:org.mitre.oval:tst:11499"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6915" version="9" class="vulnerability">
      <metadata>
        <title>WebKit HTML Image Element Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0054"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:40.262-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:32.739-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:17.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:33.077-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:51.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6915 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:33.916-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:45.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:06.251-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:28.131-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6912" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'DOCUMENT_POSITION_DISCONNECTED' Attribute Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1397"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to a layout change during selection rendering and the DOCUMENT_POSITION_DISCONNECTED attribute in a container of an unspecified type.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:47.605-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:07.982-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:17.231-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6912 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:11.159-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:01.888-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:33.593-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:50.957-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:06.951-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:27.507-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.366-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.240-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6903" version="17" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2175"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:41.261-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:03.855-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:16.831-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:26.693-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:01.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:07.558-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6903 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:31.680-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:54.476-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:18.496-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:20.422-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.826-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.243-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:19.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6903 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:08.434-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:59.280-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:122985"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:122904"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6902" version="6" class="vulnerability">
      <metadata>
        <title>Ghost Record Type Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3242" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3242"/>
        <description>Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:41.499-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:17:00.952-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:08.215-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:12.132-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:08.132-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:16.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6901" version="17" class="vulnerability">
      <metadata>
        <title>Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple Safari</product>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0043"/>
        <description>ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:37.928-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:32.493-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:17.531-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:54.061-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:26.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:39.246-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:50.610-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:46.502-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:09.072-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6901 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:31.553-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:44.936-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:15.763-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:11.509-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:14.488-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:26.535-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:56.069-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:47.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check iTunes">
          <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
          <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
        </criteria>
        <criteria operator="AND" comment="Check Safari">
          <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
          <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6900" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0199"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:39.354-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:32.069-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:17.098-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:09.208-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:12.079-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:47.993-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:49.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:35.505-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:31.117-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:09.622-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:33.949-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:37.373-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:50.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6899" version="13" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Unspecified Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3798"/>
        <description>Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:34.409-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:29.626-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:03.260-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:09.578-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:31.670-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:42.813-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:20.528-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:10:02.200-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:17.895-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:21.833-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.744-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:21.221-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:19.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6899 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:15.274-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:59.048-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:122097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6889" version="7" class="vulnerability">
      <metadata>
        <title>AutoComplete Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0808" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0808"/>
        <description>Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoComplete Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:19.958-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:09.132-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:18.123-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:02.601-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:19.006-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6889 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:53.001-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:21.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6888" version="11" class="vulnerability">
      <metadata>
        <title>WebKit UTF-7 Encoded Data Cross Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1390" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1390"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:46.100-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:07.748-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:16.612-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6888 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:12.818-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:01.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:11.634-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:49.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:35.488-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:25.994-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:53.282-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.136-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6887" version="3" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in uTorrent less than or equal to 2.0.3</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>uTorrent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3129" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3129"/>
        <description>Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse plugin_dll.dll, userenv.dll, shfolder.dll, dnsapi.dll, dwmapi.dll, iphlpapi.dll, dhcpcsvc.dll, dhcpcsvc6.dll, or rpcrtremote.dll that is located in the same folder as a .torrent or .btsearch file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-13T10:27:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:35:03.698-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:38.590-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:20.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if uTorrent version is less than or equal to 2.0.3" test_ref="oval:org.mitre.oval:tst:11353"/>
        <extend_definition comment="uTorrent is installed" definition_ref="oval:org.mitre.oval:def:7343"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7343" version="9" class="inventory">
      <metadata>
        <title>uTorrent is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>uTorrent</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:bittorrent:utorrent"/>
        <description>uTorrent is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-13T10:27:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:35:03.345-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:42.349-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:28.123-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7343 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:41.147-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:41.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7343 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:36.880-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:25.286-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7343 - Added 32-bit view to uTorrent inventory definition, and fixed CPE and title." date="2012-08-09T13:07:00.688-04:00">
              <contributor organization="Pivotal Security LLC">Gaurav Kumar</contributor>
            </modified>
            <status_change date="2012-08-09T13:49:55.539-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:40.855-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if uTorrent is installed" test_ref="oval:org.mitre.oval:tst:11013"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6886" version="10" class="vulnerability">
      <metadata>
        <title>Cabview Corruption Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Cabinet File Viewer Shell Extension</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0487"/>
        <description>The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:58.556-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:30.840-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:15.984-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:33.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.752-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.740-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6886 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:13.740-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:21.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of Cabview.dll is less than 5.0.3900.7369" test_ref="oval:org.mitre.oval:tst:11298"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.2900.3663" test_ref="oval:org.mitre.oval:tst:11381"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.2900.5927" test_ref="oval:org.mitre.oval:tst:11525"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.3790.4649" test_ref="oval:org.mitre.oval:tst:11740"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6000.17002" test_ref="oval:org.mitre.oval:tst:11864"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11560"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6000.21203" test_ref="oval:org.mitre.oval:tst:11830"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6001.18404" test_ref="oval:org.mitre.oval:tst:11297"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11529"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6001.22605" test_ref="oval:org.mitre.oval:tst:11130"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6002.18184" test_ref="oval:org.mitre.oval:tst:11490"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11204"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6002.22311" test_ref="oval:org.mitre.oval:tst:11308"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.1.7600.16500" test_ref="oval:org.mitre.oval:tst:11424"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11563"/>
          <criterion comment="the version of Cabview.dll is less than 6.1.7600.20613" test_ref="oval:org.mitre.oval:tst:11708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6885" version="17" class="vulnerability">
      <metadata>
        <title>Apple Safari BMP Image Uninitialized Memory Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple Safari</product>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0041"/>
        <description>ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:37.553-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:30.564-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:15.669-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:54.325-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:25.737-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:13.231-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:49.205-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:46.820-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:08.689-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6885 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:21.077-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:44.479-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:52:39.769-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:10.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:38.273-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:24.290-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:46.916-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:47.127-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check iTunes">
          <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
          <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
        </criteria>
        <criteria operator="AND" comment="Check Safari">
          <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
          <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6882" version="9" class="vulnerability">
      <metadata>
        <title>WebKit Object Element Fallback Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0047"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:38.991-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:30.355-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:15.459-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:12.967-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:48.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6882 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:26.165-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:44.094-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:37.919-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:23.574-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6881" version="5" class="vulnerability">
      <metadata>
        <title>Embedded OpenType Font Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1883" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1883"/>
        <description>Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:10.784-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:08.415-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:17.401-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.353-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.353-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:32.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of T2embed.dll is less than 5.1.2600.6031" test_ref="oval:org.mitre.oval:tst:11271"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of T2embed.dll is less than 5.2.3790.4766" test_ref="oval:org.mitre.oval:tst:11576"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.18520" test_ref="oval:org.mitre.oval:tst:11376"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of T2embed.dll is less than 6.0.6001.22750" test_ref="oval:org.mitre.oval:tst:11253"/>
              <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10118"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.18301" test_ref="oval:org.mitre.oval:tst:11550"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of T2embed.dll is less than 6.0.6002.22475" test_ref="oval:org.mitre.oval:tst:11549"/>
              <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10002"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.16663" test_ref="oval:org.mitre.oval:tst:11244"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of T2embed.dll is less than 6.1.7600.20788" test_ref="oval:org.mitre.oval:tst:11480"/>
              <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20099"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6880" version="9" class="vulnerability" deprecated="true">
      <metadata>
        <title>Google Chrome Nested SVG Elements Use-after-free DoS</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3410"/>
        <description>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1825.  Reason: This candidate is a duplicate of CVE-2010-1825.  Notes: All CVE users should reference CVE-2010-1825 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:03.469-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:09.789-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:05.423-04:00">ACCEPTED</status_change>
            <modified comment="Deprecated - definition was duplicate of CVE-2010-1825, please refer to that CVE." date="2010-11-22T12:00:00.000-05:00">
              <contributor organization="Critical Watch">Nelson Bunker</contributor>
            </modified>
            <status_change date="2010-11-22T12:00:00.000-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6878" version="13" class="vulnerability">
      <metadata>
        <title>Problem in handling HTML5 media in Google Chrome version less than 4.1.249.1064</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1664"/>
        <description>Google Chrome before 4.1.249.1064 does not properly handle HTML5 media, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-13T19:43:23">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:34:42.575-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:38.337-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:20.256-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11639 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:12.110-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:08.437-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:22.380-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:53.293-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:18:29.990-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:59.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:02:38.829-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:51.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:25:26.350-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:50.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check version installed is less than 4.1.249.1064" test_ref="oval:org.mitre.oval:tst:11639"/>
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6877" version="5" class="vulnerability">
      <metadata>
        <title>Excel Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1245" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1245"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:53.367-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:02.658-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:16.336-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:57.911-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:16.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6876" version="11" class="vulnerability">
      <metadata>
        <title>WebKit CSS-Styled HTML Handling Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1417"/>
        <description>The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via HTML content that contains multiple :after pseudo-selectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:50.769-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:07.525-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:16.117-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6876 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:15.744-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:00.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:16.901-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:48.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:42.854-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:22.638-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:54.603-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:03.045-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6874" version="7" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Nullsoft Winamp 5.581 and probably other versions</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Winamp</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3137" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3137"/>
        <description>Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wnaspi32.dll that is located in the same folder as a .669, .aac, .aiff, .amf, .au, .avr, .b4s, .caf or .cda file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-23T15:14:45">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-23T22:07:28.541-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:09.509-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:05.101-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7602 - New Winamp vulnerability definitions and updated objects with windows_view behavior." date="2012-07-24T13:29:00.094-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-07-24T13:37:52.702-04:00">INTERIM</status_change>
            <status_change date="2012-08-13T04:00:31.459-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7560 - new vulnerabilities on Winamp" date="2014-09-11T08:03:00.027-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-11T08:05:49.722-04:00">INTERIM</status_change>
            <status_change date="2014-09-29T04:00:26.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Winamp is installed" definition_ref="oval:org.mitre.oval:def:6897"/>
        <criteria operator="OR">
          <criterion comment="Check if the file version of Winamp.exe is less than or equal to 5.581 (5.5.8.2985)" test_ref="oval:org.mitre.oval:tst:11029"/>
          <criterion comment="Check if file version of Winamp.exe is less than or equal to 5.581 (5.5.8.2985)" test_ref="oval:org.mitre.oval:tst:11028"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6872" version="5" class="vulnerability">
      <metadata>
        <title>Negative Future Function Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3238" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3238"/>
        <description>Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:42.529-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:07.976-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:16.955-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:58.607-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:15.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11422"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6871" version="11" class="vulnerability">
      <metadata>
        <title>WebKit 'src' Attribute Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1418"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via a FRAME element with a SRC attribute composed of a javascript: sequence preceded by spaces.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:50.931-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:07.296-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:15.789-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6871 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:00.925-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:00.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:18.264-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:48.154-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:44.459-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:21.717-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:54.896-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.947-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6867" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4035"/>
        <description>Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:40.375-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:34.993-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:47.245-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:48.326-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:08.137-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:23.371-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:52.854-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:18:43.428-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:59.005-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:02:58.407-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:51.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:25:44.713-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:49.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6865" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR URI Parsing Heap Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1868"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:32.680-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:29.320-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:43:00.875-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:08.792-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:47.900-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:19.952-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:03.943-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:17.395-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:09.621-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.666-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6865 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:28.608-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:19.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6865 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:09.180-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:58.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123016"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:122750"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6862" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Fonts Handling Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1771"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving fonts.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:52.696-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:06.973-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:15.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6862 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:23.757-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:00.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:23.935-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:47.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:52.751-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:20.940-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.514-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.867-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6859" version="5" class="vulnerability">
      <metadata>
        <title>SMB Client Message Size Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0477" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0477"/>
        <description>The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:13.972-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:29.816-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:14.910-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.462-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.462-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:32.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6854" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Invalid Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2201"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:21.248-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:14.781-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:11.408-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:10.677-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:11.544-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:54.086-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:45.993-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:01.251-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:30.365-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:38.650-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:33.303-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:48.195-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:48.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6852" version="27" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player, Acrobat Reader, and Acrobat Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2884" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2884"/>
        <description>Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-16T11:38:38.693-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:37.855-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:19.424-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:11.960-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:10.975-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:57.303-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:45.260-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10958 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:30.308-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:29.351-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:42.662-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:32.330-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:20.302-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:15.561-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:54.688-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:47.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:12.688-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.514-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10958 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:00.366-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:18.989-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6852 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:07.702-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:58.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.1.82.76" test_ref="oval:org.mitre.oval:tst:10958"/>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.1.82.76" test_ref="oval:org.mitre.oval:tst:122851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6849" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2207"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:23.110-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:14.344-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:10.871-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:06.527-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:10.475-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:36.482-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:44.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:19.986-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:28.732-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:55.331-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:31.677-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:13.011-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:47.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6844" version="11" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox DOM Node Moving Use-After-Free Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1121"/>
        <description>Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:59.814-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:29.539-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:14.625-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:52.446-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:54.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6844 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:38.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:17.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:23.926-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:18.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.3" test_ref="oval:org.mitre.oval:tst:120956"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6843" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in BlackBerry Desktop Software version less than 6.0.0.47</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>BlackBerry Desktop Software</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2600" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2600"/>
        <description>Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Blackberry.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-26T10:43:26">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:33.837-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:34.508-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:46.919-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7140 - Added 32 bit behavior" date="2015-08-06T11:25:00.053-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-06T11:27:54.684-04:00">INTERIM</status_change>
            <status_change date="2015-08-24T04:00:06.716-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="BlackBerry Desktop Software is installed" definition_ref="oval:org.mitre.oval:def:6688"/>
        <criterion comment="Check if BlackBerry Desktop Software version is less than 6.0.0.47" test_ref="oval:org.mitre.oval:tst:21441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6688" version="5" class="inventory">
      <metadata>
        <title>BlackBerry Desktop Software is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>BlackBerry Desktop Software</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:rim:blackberry_desktop_software"/>
        <description>BlackBerry Desktop Software is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-26T10:43:26">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:32.929-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:30.794-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:45.730-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7233 - Added 32 bit behavior" date="2015-08-06T11:25:00.053-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-06T11:27:54.975-04:00">INTERIM</status_change>
            <status_change date="2015-08-24T04:00:06.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if BlackBerry Desktop Software is installed" test_ref="oval:org.mitre.oval:tst:21478"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6842" version="10" class="vulnerability">
      <metadata>
        <title>Excel ADO Object Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1253" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1253"/>
        <description>Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with crafted DBQueryExt records that allow a function call to a "user-controlled pointer," aka "Excel ADO Object Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:51.508-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:58.484-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:13.892-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27720 - Updated to check for Excelcnv.exe as vulnerable &amp; not Xl12cnv.exe file according to the MS Bulletin.  Also updated comments." date="2011-07-28T13:55:00.826-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-29T10:25:05.227-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:10.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:08.872-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:34.514-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:24.654-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:22.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27579"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27680"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR" comment="Check for Office 2007 or Compatibility Pack">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6535.5000" test_ref="oval:org.mitre.oval:tst:27720"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6839" version="5" class="vulnerability">
      <metadata>
        <title>Excel RTD Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1246" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1246"/>
        <description>Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:53.159-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:57.230-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:13.590-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:05.135-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:14.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6836" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Common IRC Service Port Blacklist Exclusion</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1409"/>
        <description>Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to trigger disclosure of data over IRC via vectors involving an IRC service port.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:49.622-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:06.763-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:13.364-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6836 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:15.204-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:59.867-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:29.209-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:44.287-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:00.480-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:20.484-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:52.443-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.775-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6835" version="13" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2010-0249)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0249"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-15T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-19T07:03:25.323-05:00">DRAFT</status_change>
            <modified comment="Updated title, all tests and states" date="2010-01-22T11:57:00.675-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:32:00.227-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:03.010-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:07.692-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.899-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:30.203-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:48.963-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:51.963-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:51.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:30.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:01.102-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.374-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6835 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:54.699-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6832" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-3331)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3331" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3331"/>
        <description>Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:24.861-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:07.005-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:15.955-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:51.650-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.650-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:29.800-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:59.907-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.007-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6832 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:53.987-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.6036" test_ref="oval:org.mitre.oval:tst:11894"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4772" test_ref="oval:org.mitre.oval:tst:11531"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.17092" test_ref="oval:org.mitre.oval:tst:11190"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21294" test_ref="oval:org.mitre.oval:tst:11226"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18527" test_ref="oval:org.mitre.oval:tst:11306"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22760" test_ref="oval:org.mitre.oval:tst:11235"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18309" test_ref="oval:org.mitre.oval:tst:11240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22484" test_ref="oval:org.mitre.oval:tst:11410"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64/x86, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11201"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18975" test_ref="oval:org.mitre.oval:tst:11282"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.23067" test_ref="oval:org.mitre.oval:tst:11209"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.7600.16671" test_ref="oval:org.mitre.oval:tst:11239"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
              <criterion comment="Mshtml.dll version is less than 8.0.7600.20795" test_ref="oval:org.mitre.oval:tst:11181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6831" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird, and Seamonkey Multiple XSS Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309"/>
        <description>Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:09:11.429-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:20.826-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:10.829-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:45.534-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:54.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:21.747-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:04.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6831 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:53:56.217-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:49.930-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6831 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:35.713-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:31.352-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:43.033-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6831 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:22.540-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:41.050-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.342-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:38.950-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:18.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6830" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2890"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:15.308-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:34.078-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:09.971-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:27.371-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:43.745-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:08.995-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:28.185-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:46.177-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:30.887-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:52.715-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:46.411-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:13.735-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:18.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6824" version="10" class="vulnerability">
      <metadata>
        <title>.NET Framework x64 JIT Compiler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3228"/>
        <description>The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execute arbitrary code via a crafted .NET application that triggers memory corruption, aka ".NET Framework x64 JIT Compiler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:19.917-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:21:00.547-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:07.663-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:10.998-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7311 - Corrected repeated hive element in the key" date="2010-12-31T10:57:00.761-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-31T10:58:58.150-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:19.852-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.946-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.946-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:29.198-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6824 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.227-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="os section">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="clrjit.dll version is less than 4.0.30319.202" test_ref="oval:org.mitre.oval:tst:11601"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="clrjit.dll version is greater than or equal to 4.0.30319.300" test_ref="oval:org.mitre.oval:tst:11649"/>
            <criterion comment="clrjit.dll version is less than 4.0.30319.336" test_ref="oval:org.mitre.oval:tst:11626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6823" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0194" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0194"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:37.337-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:29.116-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:14.211-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:10.028-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:09.491-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:51.580-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:43.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:38.097-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:27.528-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:11.809-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:30.197-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:44.790-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:45.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6819" version="5" class="vulnerability">
      <metadata>
        <title>Visio Attribute Validation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office Visio 2002</product>
          <product>Microsoft Office Visio 2003</product>
          <product>Microsoft Office Visio 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0254"/>
        <description>Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:43:19.075-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:28.312-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:13.396-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11684 - Updates to Visio related definitions to fix Object collection concerns." date="2013-01-22T15:55:00.810-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-22T16:11:07.709-05:00">INTERIM</status_change>
            <status_change date="2013-02-11T04:03:29.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Office Visio 2002 SP2">
          <extend_definition comment="Microsoft Office Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Vislib.dll version is less than 10.0.6890.4" test_ref="oval:org.mitre.oval:tst:11684"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office Visio 2003">
          <extend_definition comment="Microsoft Office Visio 2003 is installed" definition_ref="oval:org.mitre.oval:def:1450"/>
          <criterion comment="Vislib.dll version is less than 11.0.8321.0" test_ref="oval:org.mitre.oval:tst:11535"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office Visio 2007">
          <extend_definition comment="Microsoft Office Visio 2007 is installed" definition_ref="oval:org.mitre.oval:def:5261"/>
          <criterion comment="Vislib.dll version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:11437"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6817" version="9" class="vulnerability">
      <metadata>
        <title>Apple Safari URL Schemes Handling Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0045"/>
        <description>Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:38.664-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:28.085-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:13.180-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:38.375-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:42.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6817 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:17.947-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:43.728-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:13.331-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:19.679-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6813" version="13" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to bypass the Origin Policy  in Google Chrome version less than 4.1.249.1064</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1663"/>
        <description>The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-13T19:43:23">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-17T15:34:42.792-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:37.338-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:18.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11639 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:12.464-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:07.789-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:59:04.222-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:52.477-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:22:54.452-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:58.604-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:07:48.335-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:50.566-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:32:08.637-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:45.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check version installed is less than 4.1.249.1064" test_ref="oval:org.mitre.oval:tst:11639"/>
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6812" version="11" class="vulnerability">
      <metadata>
        <title>Apple Safari URL Obfuscation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1384"/>
        <description>Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:45.326-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:06.535-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:13.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6812 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:03.228-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:59.548-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:36.489-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:42.565-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:10.797-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:18.983-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:56.662-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.693-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6811" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772"/>
        <description>The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:03:50.643-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:20.413-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:10.436-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:41.969-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:01.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:04.309-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:53.829-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:39.642-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:03.803-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6811 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:15.394-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:49.776-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6811 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:35.414-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:31.174-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:45.275-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6811 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:22.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:43.302-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:19.967-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:41.661-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:18.209-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6810" version="9" class="vulnerability">
      <metadata>
        <title>WebKit Right-to-Left Displayed Text Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0049"/>
        <description>Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:39.372-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:27.070-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:12.116-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:36.267-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:42.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6810 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:25.001-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:43.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:10.453-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:18.419-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6807" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
          <product>RealPlayer SP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0120"/>
        <description>Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:25.542-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:09.172-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:04.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer SP is greater than or equal to 1.0" test_ref="oval:org.mitre.oval:tst:11442"/>
            <criterion comment="Check if the version of RealPlayer SP is less than 1.1.5" test_ref="oval:org.mitre.oval:tst:11165"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
            <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6806" version="5" class="vulnerability">
      <metadata>
        <title>TLSv1 Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3229" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3229"/>
        <description>The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-18T21:50:31.852-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:06.309-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:15.318-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:54.603-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:54.603-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:28.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6001.18507" test_ref="oval:org.mitre.oval:tst:11456"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:41291"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6001.22739" test_ref="oval:org.mitre.oval:tst:11696"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6002.18290" test_ref="oval:org.mitre.oval:tst:11915"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:41611"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6002.22463" test_ref="oval:org.mitre.oval:tst:11148"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.1.7600.16661" test_ref="oval:org.mitre.oval:tst:11477"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:41670"/>
              <criterion comment="the version of schannel.dll is less than 6.1.7600.20785" test_ref="oval:org.mitre.oval:tst:11405"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6803" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1287"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:47.314-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:29.735-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:08.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:07.698-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:32.664-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6801" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 FLC Encoded Movie Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0520" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0520"/>
        <description>Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length values in a .fli file, which are not properly handled during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:56.266-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:26.697-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:11.834-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:08.976-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:42.060-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:35.124-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:19.639-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6801 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:21.107-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:42.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6798" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2212"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:24.957-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:12.646-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:10.419-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:11.228-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:08.559-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:55.190-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:41.529-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:40.119-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:26.888-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:13.550-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:28.594-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:49.662-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:44.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6795" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Unspecified Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4324"/>
        <description>Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T17:00:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2009-12-15T20:19:45.580-05:00">DRAFT</status_change>
            <modified comment="Add adobe reader 8.0, check for library version 8.1.7.  Add adobe reader 9.0, check for library version 9.2.0.  Add adobe acrobat 8.0, check for library version 8.1.7.  Add adobe acrobat 9.0, check for library version 9.2.0" date="2009-12-17T11:50:00.331-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:55.183-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:25.719-05:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:11.763-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:08.091-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:56.233-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:40.924-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:44.275-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:26.258-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:17.498-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:27.213-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:53.403-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:43.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal 8.1.7" test_ref="oval:org.mitre.oval:tst:11276"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.1.7" test_ref="oval:org.mitre.oval:tst:11095"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal 9.2.0" test_ref="oval:org.mitre.oval:tst:11041"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.2.0" test_ref="oval:org.mitre.oval:tst:11124"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal 8.1.7" test_ref="oval:org.mitre.oval:tst:11173"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.1.7" test_ref="oval:org.mitre.oval:tst:11202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal 9.2.0" test_ref="oval:org.mitre.oval:tst:11321"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.2.0" test_ref="oval:org.mitre.oval:tst:11038"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6792" version="6" class="vulnerability">
      <metadata>
        <title>Word Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3220" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3220"/>
        <description>Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:34.857-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:29:00.662-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:07.173-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:10.496-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:39.472-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:14.254-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6791" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Denial of Service Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3657"/>
        <description>Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:20.820-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:33.314-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:07.638-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:58.854-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:40.423-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:46.905-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:25.678-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:19.846-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:26.331-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:57.693-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:43.125-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.817-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:17.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6790" version="13" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Google Chrome before 7.0.517.41 allows remote attackers to bypass the pop-up blocker via unknown vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4037"/>
        <description>Unspecified vulnerability in Google Chrome before 7.0.517.41 allows remote attackers to bypass the pop-up blocker via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:40.804-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:32.986-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:46.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:50.142-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:07.446-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:28.344-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:52.114-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:20:15.462-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:58.211-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:05:03.380-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:50.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:27:50.725-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:42.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6787" version="10" class="vulnerability">
      <metadata>
        <title>WinVerifyTrust Signature Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Authenticode Signature Verification</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0486"/>
        <description>The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:56.734-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:25.389-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:10.246-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.384-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.384-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:27.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.423-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:17.736-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6787 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:15.000-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:19.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2195.7375" test_ref="oval:org.mitre.oval:tst:11686"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2600.3661" test_ref="oval:org.mitre.oval:tst:11304"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2600.5922" test_ref="oval:org.mitre.oval:tst:11690"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 5.131.3790.4642" test_ref="oval:org.mitre.oval:tst:11359"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6000.16984" test_ref="oval:org.mitre.oval:tst:11719"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11349"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6000.21186" test_ref="oval:org.mitre.oval:tst:11492"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6001.18387" test_ref="oval:org.mitre.oval:tst:11262"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11526"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6001.22588" test_ref="oval:org.mitre.oval:tst:11567"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6002.18169" test_ref="oval:org.mitre.oval:tst:11040"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11196"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6002.22293" test_ref="oval:org.mitre.oval:tst:11738"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.1.7600.16493" test_ref="oval:org.mitre.oval:tst:11401"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11722"/>
          <criterion comment="the version of wintrust.dll is less than 6.1.7600.20605" test_ref="oval:org.mitre.oval:tst:11330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6783" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 H.264 Encoded Movie Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0515" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0515"/>
        <description>QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with H.264 encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:57.103-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:25.130-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:09.875-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:08.531-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:40.143-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:34.205-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:19.320-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6783 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:47.349-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:42.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6781" version="17" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2165"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:39.082-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:54.869-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:12.305-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:27.041-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:59.162-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:07.930-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6781 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:25.235-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:34.483-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:14.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:15.363-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.356-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:06.425-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:17.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6781 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:13.692-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:58.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:122985"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:122904"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6780" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 PICT Image Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0529"/>
        <description>Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:55.740-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:24.860-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:09.625-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:06.886-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:39.844-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:32.613-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:18.948-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6780 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:04.651-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:41.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6778" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Photoshop</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3127"/>
        <description>Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-28T12:30:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:10.172-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:10.391-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:05.576-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7060 - PhotoShop CS2 - CS5 is Adobe Photoshop 9-12, not 7-12." date="2015-07-15T15:03:00.398-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-15T15:05:14.687-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:57.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Adobe Photoshop is installed" definition_ref="oval:org.mitre.oval:def:6647"/>
        <criteria operator="AND">
          <criterion comment="Check if the version of Adobe Photoshop is greater than or equal to 9.0" test_ref="oval:org.mitre.oval:tst:11517"/>
          <criterion comment="Check if the version of Adobe Photoshop is less than or equal to 12.0" test_ref="oval:org.mitre.oval:tst:11351"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6776" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and SeaMonkey mailto: URL Redirection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla SeaMonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0181"/>
        <description>Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-05T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:53:04.066-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:24.527-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:09.268-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:40.733-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:53.371-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:33.304-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:03.370-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6776 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:52.224-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:49.639-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5575 - oval:org.mitre.oval:obj:29583 (file_object) is only object which checks SeaMonkey version correctly" date="2014-03-06T11:20:00.847-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-06T11:22:52.737-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:53.046-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6776 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:32.836-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:17.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:14.630-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:17.610-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x before 3.5.9" test_ref="oval:org.mitre.oval:tst:120877"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.6.x before 3.6.2" test_ref="oval:org.mitre.oval:tst:120827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0.4" test_ref="oval:org.mitre.oval:tst:100080"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6775" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome before 7.0.517.41 does not properly handle forms</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4034"/>
        <description>Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:40.160-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:32.536-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:46.002-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:49.829-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:07.137-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:25.990-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:51.712-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:19:33.587-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:57.780-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:04:10.515-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:49.684-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:26:53.884-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:42.127-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6773" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability via a Trojan horse dwmapi.dll in TeamViewer version less than or equal to 5.0.8703</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>TeamViewer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3128"/>
        <description>Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .tvs or .tvc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-30T08:01:50">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:18.467-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:10.102-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:05.282-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7561 - Added 32 bit behavior because TeamViewer is 32-bit application" date="2013-11-26T15:05:00.885-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-26T15:07:56.108-05:00">INTERIM</status_change>
            <status_change date="2013-12-16T04:01:50.804-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="TeamViewer is installed" definition_ref="oval:org.mitre.oval:def:7018"/>
        <criterion comment="Check if TeamViewer version is less than or equal to 5.0.8703" test_ref="oval:org.mitre.oval:tst:11546"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7018" version="5" class="inventory">
      <metadata>
        <title>TeamViewer is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>TeamViewer</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:teamviewer:teamviewer"/>
        <description>TeamViewer is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-30T08:01:50">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:17.960-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:10.853-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:10.569-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7388 - Added windows_view=&quot;32_bit&quot; behavior." date="2012-10-12T16:18:00.670-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-10-12T16:18:45.510-04:00">INTERIM</status_change>
            <status_change date="2012-10-29T04:00:09.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if TeamViewer is installed" test_ref="oval:org.mitre.oval:tst:11668"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6772" version="19" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Prefix Protocol Handler Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3625"/>
        <description>Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-08T17:30:00.000-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:17.207-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:32.106-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:07.208-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:39.884-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:39.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:25.861-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:24.606-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:59.355-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:25.657-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:21.607-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:41.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:41821 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:15.530-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:17.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41592"/>
            <criterion comment="Adobe Reader library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41646"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41821"/>
            <criterion comment="Adobe Reader library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41570"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:41490"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 9.3.4" test_ref="oval:org.mitre.oval:tst:40970"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:41728"/>
            <criterion comment="Adobe Acrobat library is less than or equal to 8.2.4" test_ref="oval:org.mitre.oval:tst:40904"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6771" version="12" class="vulnerability">
      <metadata>
        <title>Excel Record Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0821" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0821"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with a crafted SxView record, related to improper validation of unspecified structures, aka "Excel Record Parsing Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-1245.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:54.942-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:53.842-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:11.771-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27720 - Updated to check for Excelcnv.exe as vulnerable &amp; not Xl12cnv.exe file according to the MS Bulletin.  Also updated comments." date="2011-07-28T13:55:00.826-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-29T10:25:04.733-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:09.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:15.663-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:33.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:57.318-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:32.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:07.933-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:22.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8324.0" test_ref="oval:org.mitre.oval:tst:27579"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2007">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6535.5002" test_ref="oval:org.mitre.oval:tst:27680"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel Viewer 2007">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6535.5000" test_ref="oval:org.mitre.oval:tst:27301"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Compatibility Pack, Office 2007">
          <criteria operator="OR" comment="Check for Office 2007 or Compatibility Pack">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6535.5000" test_ref="oval:org.mitre.oval:tst:27720"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6770" version="5" class="vulnerability">
      <metadata>
        <title>Windows Virtual Path Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0481" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0481"/>
        <description>The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:29.838-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:23.884-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:08.530-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:26.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.17021" test_ref="oval:org.mitre.oval:tst:11259"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21226" test_ref="oval:org.mitre.oval:tst:11841"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18427" test_ref="oval:org.mitre.oval:tst:11737"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22636" test_ref="oval:org.mitre.oval:tst:11674"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18209" test_ref="oval:org.mitre.oval:tst:11433"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22341" test_ref="oval:org.mitre.oval:tst:11585"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11261"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6768" version="5" class="vulnerability">
      <metadata>
        <title>Excel Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0824" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0824"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:53.569-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:53.554-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:11.463-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:02.530-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:13.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6766" version="17" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2170" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2170"/>
        <description>Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2181 and CVE-2010-2183.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:40.181-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:52.743-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:11.135-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:28.358-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:58.746-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:09.691-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6766 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:24.165-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:08.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:14.365-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:10.480-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.278-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.075-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:17.173-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6766 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:10.171-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:57.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:122985"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:122904"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6765" version="17" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Use-After-Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2164"/>
        <description>Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to an unspecified "image type within a certain function."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:38.780-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:52.445-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:10.723-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:28.992-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:58.381-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:10.525-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6765 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:23.691-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:09.305-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:13.816-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:10.577-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.197-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:07.350-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:16.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6765 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:07.409-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:57.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:122985"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:122904"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6762" version="17" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Invalid Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2173"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors, related to an "invalid pointer vulnerability" and the newclass (0x58) operator, a different vulnerability than CVE-2010-2174.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:40.681-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:52.139-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:10.364-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:25.677-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:57.951-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:06.345-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6762 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:23.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:03.480-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:13.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:09.538-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:24.118-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:05.858-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:16.682-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6762 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:14.713-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:57.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:122985"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:122904"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6761" version="5" class="vulnerability">
      <metadata>
        <title>Excel Record Stack Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1251" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1251"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:52.081-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:51.777-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:10.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:01.857-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:12.666-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6758" version="17" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2182"/>
        <description>Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-11T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-14T13:15:43.147-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:50.856-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:09.685-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27545 - Changed operation to 'less than or equal'" date="2011-02-22T12:45:00.599-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:50:32.748-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:57.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:27443 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:14.998-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6758 - Fix to check additional vulnerable versions of Adobe Flash/AIR." date="2012-12-27T15:16:00.909-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-14T04:03:22.642-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:19.190-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:12.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:12.414-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.989-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6916 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:08.888-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:16.452-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6758 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:15.930-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:56.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if Adobe AIR version is less than or equal 1.5.3.9130" test_ref="oval:org.mitre.oval:tst:27545"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
          <criteria operator="AND" comment="Adobe Flash Player before 9.0.277.0 installed">
            <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:80169"/>
          </criteria>
          <criteria operator="AND" comment="Adobe Flash Player 10.x through 10.0.45.2 installed">
            <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:27443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criteria operator="AND" comment="Flash.ocx 10 section">
              <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.45.2" test_ref="oval:org.mitre.oval:tst:122985"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            </criteria>
            <criteria operator="AND" comment="Flash.ocx 9 section">
              <criterion comment="Determine if the version of Flash.ocx is less than 9.0.277.0" test_ref="oval:org.mitre.oval:tst:122904"/>
              <criterion comment="Determine if the version of Flash.ocx is greater than or equal 9.0" test_ref="oval:org.mitre.oval:tst:122187"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6755" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey memory corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0771"/>
        <description>The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:03:32.305-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:19.530-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:09.962-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:44.756-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:01:00.734-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:28.907-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:52.823-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:13.970-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:02.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6755 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:48.019-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:49.399-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6755 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:38.437-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:30.994-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:05.172-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6755 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:21.942-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:00.728-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:19.457-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:53.306-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:16.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6748" version="7" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in Apple Safari 4.0.5</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1939" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1939"/>
        <description>Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-17T03:34:03">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-05-17T15:31:42.917-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:08.211-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:05.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:13.513-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:38.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:38.814-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:17.798-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6747" version="10" class="vulnerability">
      <metadata>
        <title>Apple Quicktime Picture Viewer DLL Search Path Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1819"/>
        <description>Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) CoreVideo.dll, (2) CoreGraphics.dll, or (3) CoreAudioToolbox.dll that is located in the same folder as a .pic image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-16T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-16T11:38:41.703-04:00">DRAFT</status_change>
            <status_change date="2010-10-04T04:00:37.136-04:00">INTERIM</status_change>
            <status_change date="2010-10-25T04:00:18.346-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:08.753-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:38.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:34.464-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:18.617-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6747 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:22.371-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:41.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.8 (7.68.75.0)" test_ref="oval:org.mitre.oval:tst:11363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6741" version="17" class="vulnerability">
      <metadata>
        <title>Apple Safari Prior to 4.0.5 Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple Safari</product>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0040"/>
        <description>Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-09T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-13T10:01:37.072-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:23.616-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:07.882-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:53.767-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:25.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:11.952-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:38.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:46.177-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:08.244-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6741 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:18.659-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:41.085-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6741 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:51:19.873-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:10.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:35.878-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:16.973-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:46.615-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:46.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check iTunes">
          <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
          <criterion comment="iTunes.exe version is less than 9.1.0.79" test_ref="oval:org.mitre.oval:tst:11287"/>
        </criteria>
        <criteria operator="AND" comment="Check Safari">
          <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
          <criterion comment="Apple Safari version is less than 5.31.22.7" test_ref="oval:org.mitre.oval:tst:11487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6739" version="11" class="vulnerability">
      <metadata>
        <title>WebKit JavaScript 'execCommand' Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1421"/>
        <description>The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict remote execution of clipboard commands, which allows remote attackers to modify the clipboard via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:51.291-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:05.659-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:09.445-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6739 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:24.327-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:57.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:18.582-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:37.874-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:44.879-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:16.413-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.047-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.609-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6738" version="6" class="vulnerability">
      <metadata>
        <title>Out-of-Bounds Memory Write in Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3241" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3241"/>
        <description>Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:41.706-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:34:00.262-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:06.367-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:09.597-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:58.950-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:11.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6737" version="5" class="vulnerability">
      <metadata>
        <title>Lotus 1-2-3 Workbook Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3233" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3233"/>
        <description>Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:43.660-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:04.255-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:13.990-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:00.133-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:11.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2003">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8328.0" test_ref="oval:org.mitre.oval:tst:11422"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6734" version="10" class="vulnerability">
      <metadata>
        <title>Outlook Express and Windows Mail Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Outlook Express</product>
          <product>Microsoft Windows Mail</product>
          <product>Microsoft Windows Live Mail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816"/>
        <description>Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-05-12T12:23:25.542-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:28.757-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:05.608-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.244-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.244-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:24.920-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6734 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:29.064-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:08.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6734 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:13.458-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:18.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 5.5 SP2 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of Inetcomm.dll is less than 5.50.5010.200" test_ref="oval:org.mitre.oval:tst:11816"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 SP1 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2800.2001" test_ref="oval:org.mitre.oval:tst:11216"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.3664" test_ref="oval:org.mitre.oval:tst:11320"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.5931" test_ref="oval:org.mitre.oval:tst:10972"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP (64-bit), Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP (64-bit), Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.4657" test_ref="oval:org.mitre.oval:tst:11267"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18416" test_ref="oval:org.mitre.oval:tst:11337"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22621" test_ref="oval:org.mitre.oval:tst:11718"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18197" test_ref="oval:org.mitre.oval:tst:11803"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22325" test_ref="oval:org.mitre.oval:tst:11524"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail Windows Server 2008 ia64 - GDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18427" test_ref="oval:org.mitre.oval:tst:11799"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - LDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22636" test_ref="oval:org.mitre.oval:tst:11536"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - GDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18209" test_ref="oval:org.mitre.oval:tst:11316"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - LDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22341" test_ref="oval:org.mitre.oval:tst:11688"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.16543" test_ref="oval:org.mitre.oval:tst:11904"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11895"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.20659" test_ref="oval:org.mitre.oval:tst:11232"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2058" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows Mail is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Windows Mail</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_mail"/>
        <description>Microsoft Windows Mail is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T12:32:06.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected regex in ste:3814 to account for both commas and dots, also anchored the boundaries." date="2007-06-15T13:10:00.106-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:59.294-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:52.876-04:00">ACCEPTED</status_change>
            <modified comment="Corrected comment for oval:org.mitre.oval:tst:3506 and updated ste:3814 to match with newer versions of Windows Mail 6.0." date="2010-05-12T11:21:00.138-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-12T11:23:48.997-04:00">INTERIM</status_change>
            <modified comment="Added new test to check for Windows Mail 6.1" date="2010-05-12T11:57:00.591-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:05.436-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.275-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.275-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:59.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Windows Mail version 6.0" test_ref="oval:org.mitre.oval:tst:3506"/>
        <criterion comment="Windows Mail version 6.1" test_ref="oval:org.mitre.oval:tst:11318"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6733" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0202"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:40.093-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:22.974-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:07.273-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:07.033-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:06.701-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:38.821-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:37.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:43.417-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:21.772-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:42:22.084-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:24.790-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:20.230-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:40.659-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6732" version="5" class="vulnerability">
      <metadata>
        <title>Visio Index Calculation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office Visio 2002</product>
          <product>Microsoft Office Visio 2003</product>
          <product>Microsoft Office Visio 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0256"/>
        <description>Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:43:19.367-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:22.612-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:06.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11684 - Updates to Visio related definitions to fix Object collection concerns." date="2013-01-22T15:55:00.810-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-22T16:11:08.104-05:00">INTERIM</status_change>
            <status_change date="2013-02-11T04:03:24.169-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Office Visio 2002 SP2">
          <extend_definition comment="Microsoft Office Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Vislib.dll version is less than 10.0.6890.4" test_ref="oval:org.mitre.oval:tst:11684"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office Visio 2003">
          <extend_definition comment="Microsoft Office Visio 2003 is installed" definition_ref="oval:org.mitre.oval:def:1450"/>
          <criterion comment="Vislib.dll version is less than 11.0.8321.0" test_ref="oval:org.mitre.oval:tst:11535"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Office Visio 2007">
          <extend_definition comment="Microsoft Office Visio 2007 is installed" definition_ref="oval:org.mitre.oval:def:5261"/>
          <criterion comment="Vislib.dll version is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:11437"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6731" version="10" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox and Seamonkey XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Seamonkey</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312"/>
        <description>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:09:47.787-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:18.958-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:09.594-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:06.486-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:51.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:59:52.147-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:02.307-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6731 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:16.881-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:49.267-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6731 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:33.859-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:30.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:99880"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6729" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Prefix Protocol Handler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0191"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-13T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:36.248-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:22.183-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:06.348-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:11.883-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:06.241-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:56.744-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:36.721-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:43.711-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:21.100-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:16.891-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:23.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:54.088-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:39.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11310"/>
            <criterion comment="Adobe Reader library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11712"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11687"/>
            <criterion comment="Adobe Reader library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11053"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11064"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.2" test_ref="oval:org.mitre.oval:tst:11538"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11242"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.2" test_ref="oval:org.mitre.oval:tst:11234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6727" version="6" class="vulnerability">
      <metadata>
        <title>Merge Cell Record Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3237" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3237"/>
        <description>Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:42.763-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:35:00.130-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:05.964-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:09.284-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:09.272-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:10.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
        <criterion comment="Excel.exe version is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11175"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6725" version="18" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Invalid Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1285"/>
        <description>Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified manipulations involving the newclass (0x58) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-2168 and CVE-2010-2201.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-29T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-30T10:32:20.162-04:00">DRAFT</status_change>
            <status_change date="2010-07-19T04:00:08.826-04:00">INTERIM</status_change>
            <status_change date="2010-08-09T04:00:09.692-04:00">ACCEPTED</status_change>
            <modified comment="Correction to key in obj:7398" date="2010-11-29T16:14:00.048-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-11-29T16:25:09.333-05:00">INTERIM</status_change>
            <modified comment="Correction to key in obj:7190" date="2010-11-29T16:25:00.726-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2010-12-20T04:01:05.681-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:167 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:39:48.528-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:36.140-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:36.577-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:20.000-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:43:10.240-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:21.934-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:38.748-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:39.167-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27254"/>
            <criterion comment="Adobe Reader library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27033"/>
            <criterion comment="Adobe Reader library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27605"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27610"/>
            <criterion comment="Adobe Acrobat library is less than 8.2.3" test_ref="oval:org.mitre.oval:tst:27747"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 9, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27382"/>
            <criterion comment="Adobe Acrobat library is less than 9.3.3" test_ref="oval:org.mitre.oval:tst:27716"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6717" version="9" class="vulnerability" deprecated="true">
      <metadata>
        <title>Google Chrome SVG Style Use-after-free DoS</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3409"/>
        <description>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1824.  Reason: This candidate is a duplicate of CVE-2010-1824.  Notes: All CVE users should reference CVE-2010-1824 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-17T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:03.254-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:08.855-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:04.360-04:00">ACCEPTED</status_change>
            <modified comment="Deprecated - definition was duplicate of CVE-2010-1824, please refer to that CVE." date="2010-11-22T12:00:00.000-05:00">
              <contributor organization="Critical Watch">Nelson Bunker</contributor>
            </modified>
            <status_change date="2010-11-22T12:00:00.000-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6550 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.59" test_ref="oval:org.mitre.oval:tst:11255"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6716" version="37" class="vulnerability">
      <metadata>
        <title>ATL COM Initialization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Outlook 2002</product>
          <product>Microsoft Outlook 2003</product>
          <product>Microsoft Outlook 2007</product>
          <product>Microsoft Visio Viewer 2002</product>
          <product>Microsoft Office Visio Viewer 2003</product>
          <product>Microsoft Office Visio Viewer 2007</product>
          <product>Microsoft Internet Explorer 5</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Visual Studio .NET 2003</product>
          <product>Microsoft Visual Studio 2005</product>
          <product>Microsoft Visual Studio 2008</product>
          <product>Microsoft Visual C++ 2005 Redistributable Package</product>
          <product>Microsoft Visual C++ 2008 Redistributable Package</product>
          <product>Microsoft Outlook Express 5.5</product>
          <product>Microsoft Outlook Express 6.0</product>
          <product>Windows Media Player 9</product>
          <product>Windows Media Player 10</product>
          <product>Windows Media Player 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493"/>
        <description>The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:10:45.408-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:15.288-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:07.060-05:00">ACCEPTED</status_change>
            <modified comment="Edited var:489 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:42:00.629-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-13T15:45:06.964-04:00">INTERIM</status_change>
            <modified comment="Edited var:569 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:45:00.272-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited var:562 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:45:00.580-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited var:820 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:47:00.368-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:24.789-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6716 - MS09-037 Revision 2 released new updates for HtmlInput Object ActiveX  control. Added HtmlInput Object ActiveX control for WinVista and version corrected in ste:5076." date="2011-10-28T20:15:00.526-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-28T20:59:38.885-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:820 - updated oval:org.mitre.oval:var:820 to match multiple file versions" date="2011-10-31T09:26:00.226-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:var:569 - updated oval:org.mitre.oval:var:569 to match multiple file versions" date="2011-10-31T09:26:00.834-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:tst:10299 - updated comment" date="2011-10-31T09:38:00.588-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:tst:10457 - updated comment" date="2011-10-31T09:38:00.531-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-11-21T04:13:15.413-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6716 - issue with the ATL90.dll and made the corrections for all the affected definitions" date="2011-11-29T11:12:00.490-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-11-29T11:13:56.956-05:00">INTERIM</status_change>
            <status_change date="2011-12-19T04:00:48.706-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:48.775-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:48.775-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:21.619-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:247 - Updating pre-Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:55:00.075-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:56:53.447-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:30.364-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6716 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:37.764-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:05.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10291 - improve the vulnerability detection on Windows XP, Vista, Server 2003 and 2008." date="2013-02-25T15:00:00.883-05:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-02-25T15:13:17.597-05:00">INTERIM</status_change>
            <status_change date="2013-03-18T04:00:27.667-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6924 - Updated to support both native and 32-bit views" date="2013-08-14T09:49:00.871-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-08-14T09:51:28.299-04:00">INTERIM</status_change>
            <status_change date="2013-09-02T04:05:49.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6623 - Corrected objects comments to match files referenced by the objects" date="2014-01-30T14:43:00.361-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:45:29.937-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:38.988-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9962 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:43.238-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:29.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10001 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-30T10:26:24.744-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:21.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6716 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:32.217-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:17.849-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6716 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:35:00.796-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:37:47.978-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:01:07.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3882.2700" test_ref="oval:org.mitre.oval:tst:11030"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Internet Explorer 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS">
            <criteria operator="AND" comment="Check for vulnerable Windows 2000">
              <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
              <criterion comment="Mshtml.dll version is less than 6.0.2800.1642" test_ref="oval:org.mitre.oval:tst:10363"/>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable Windows XP (x86)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Mshtml.dll version is less than 6.0.2900.3640" test_ref="oval:org.mitre.oval:tst:11188"/>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable Windows XP (x86)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Mshtml.dll version is less than 6.0.2900.5897" test_ref="oval:org.mitre.oval:tst:11032"/>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable OS">
              <criteria operator="OR" comment="Check for vulnerable Windows XP x64/Windows Server 2003 (x86)/(x64)/(ia64)">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Mshtml.dll version is less than 6.0.3790.4611" test_ref="oval:org.mitre.oval:tst:11149"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Outlook 2002">
          <extend_definition comment="Microsoft Outlook 2002 is installed" definition_ref="oval:org.mitre.oval:def:5179"/>
          <criterion comment="the version of Outllib.dll is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:10332"/>
        </criteria>
        <criteria operator="AND" comment="Outlook 2003">
          <extend_definition comment="Microsoft Outlook 2003 is installed" definition_ref="oval:org.mitre.oval:def:5505"/>
          <criterion comment="the version of Outllib.dll is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:10969"/>
        </criteria>
        <criteria operator="AND" comment="Outlook 2007">
          <criteria operator="OR" comment="Microsoft Outlook 2007">
            <extend_definition comment="Microsoft Outlook 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:18961"/>
            <extend_definition comment="Microsoft Outlook 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:18844"/>
          </criteria>
          <criterion comment="the version of Outlook.exe is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:10983"/>
        </criteria>
        <extend_definition comment="Microsoft Visio Viewer 2002 is installed" definition_ref="oval:org.mitre.oval:def:6500"/>
        <extend_definition comment="Microsoft Office Visio Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:6420"/>
        <criteria operator="AND" comment="Microsoft Office Visio Viewer 2007">
          <extend_definition comment="Microsoft Office Visio Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6128"/>
          <criterion comment="the version of Vviewer.dll is less than 12.0.6513.5000" test_ref="oval:org.mitre.oval:tst:10549"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows OS and Vulnerable ActiveX">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable ActiveX">
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10568"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10739"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10428"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10956"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10741"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10559"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10837"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10923"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10592"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10657"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10978"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10876"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10927"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10844"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:11009"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10968"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10708"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10997"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10786"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10822"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10892"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10680"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10951"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10887"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10198"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10986"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10698"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10823"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10819"/>
            <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10829"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio .NET 2003 SP1">
          <extend_definition comment="Microsoft Visual Studio .NET 2003 SP1 is installed" definition_ref="oval:org.mitre.oval:def:168"/>
          <criterion comment="the version of Mfc71.dll is less than 7.10.6101.0" test_ref="oval:org.mitre.oval:tst:10101"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio 2005 SP1">
          <extend_definition comment="Microsoft Visual Studio 2005 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6401"/>
          <criterion comment="the version of ATL80.dll is less than 8.0.50727.4053" test_ref="oval:org.mitre.oval:tst:9486"/>
          <criterion comment="ATL80.dll exists" test_ref="oval:org.mitre.oval:tst:115216"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio 2008">
          <extend_definition comment="Microsoft Visual Studio 2008 is installed" definition_ref="oval:org.mitre.oval:def:5401"/>
          <criterion comment="the version of ATL90.dll is less than 9.0.21022.218" test_ref="oval:org.mitre.oval:tst:10046"/>
          <criterion comment="ATL90.dll exists" test_ref="oval:org.mitre.oval:tst:115651"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio 2008 SP1">
          <extend_definition comment="Microsoft Visual Studio 2008 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6205"/>
          <criterion comment="the version of ATL90.dll is less than 9.0.30729.4148" test_ref="oval:org.mitre.oval:tst:10261"/>
          <criterion comment="ATL90.dll exists" test_ref="oval:org.mitre.oval:tst:115651"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual C++ 2005 Redistributable Package">
          <extend_definition comment="Microsoft Visual C++ 2005 Redistributable Package is installed" definition_ref="oval:org.mitre.oval:def:29007"/>
          <criteria operator="OR" comment="atl80.dll version">
            <criterion comment="the version of %SystemRoot%\WinSxS\(x86|amd64)_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.[0-9]{1,4}.*\atl80.dll is less than 8.0.50727.4053" test_ref="oval:org.mitre.oval:tst:10299"/>
            <criterion comment="the version of %SystemRoot%\winsxs\(x86|amd64)_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.[0-9]{1,4}.*\atl80.dll is less than 8.0.50727.4053" test_ref="oval:org.mitre.oval:tst:10457"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual C++ 2008 Redistributable Package">
          <extend_definition comment="Microsoft Visual C++ 2008 Redistributable Package is installed" definition_ref="oval:org.mitre.oval:def:28587"/>
          <criteria operator="OR" comment="atl90.dll version">
            <criterion comment="the version of %SystemRoot%\WinSxS\(x86|amd64)_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.[0-9]{1,4}.*\atl90.dll is less than 9.0.30729.4148" test_ref="oval:org.mitre.oval:tst:10393"/>
            <criterion comment="the version of %SystemRoot%\winsxs\(x86|amd64)_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.[0-9]{1,4}.*\atl90.dll is less than 9.0.30729.4148" test_ref="oval:org.mitre.oval:tst:9962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 5.5 SP2 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of Msoe.dll is less than 5.50.5003.1000" test_ref="oval:org.mitre.oval:tst:10492"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 SP1 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of Msoe.dll is less than 6.0.2800.1983" test_ref="oval:org.mitre.oval:tst:10100"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criteria operator="OR" comment="Check for affected platforms with vulnerable file">
            <criteria operator="AND" comment="Check for Windows XP x86">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="the version of Msoe.dll is less than 6.0.2900.3598" test_ref="oval:org.mitre.oval:tst:9966"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP x86">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="the version of Msoe.dll is less than 6.0.2900.5843" test_ref="oval:org.mitre.oval:tst:10297"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP (64-bit) and 2003 x86/x64/ia64">
              <criteria operator="OR" comment="OS Check">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="the version of Msoe.dll is less than 6.0.3790.4548" test_ref="oval:org.mitre.oval:tst:10588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 9 on Windows 2000 (KB973540)">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criteria operator="OR" comment="file checks">
            <criterion comment="the version of Wmp.dll is less than 9.0.0.3364" test_ref="oval:org.mitre.oval:tst:10677"/>
            <criterion comment="Wmpdxm.dll version is less than 9.0.0.3364" test_ref="oval:org.mitre.oval:tst:80889"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 9 on Windows XP x86 (KB973540)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criteria operator="OR" comment="file checks">
            <criterion comment="the version of Wmp.dll is less than 9.0.0.3364" test_ref="oval:org.mitre.oval:tst:10677"/>
            <criterion comment="Wmpdxm.dll version is less than 9.0.0.3364" test_ref="oval:org.mitre.oval:tst:80889"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 9 on Windows XP x86 (KB973540)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criteria operator="OR" comment="file checks">
            <criterion comment="Wmp.dll version is less than 9.0.0.4507" test_ref="oval:org.mitre.oval:tst:10010"/>
            <criterion comment="Wmpdxm.dll version is less than 9.0.0.4507" test_ref="oval:org.mitre.oval:tst:80904"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP x86/x64, Server 2003 x86/x64 (KB973540)">
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criteria operator="OR" comment="Check for affected platforms with vulnerable file">
            <criteria operator="AND" comment="Check for Windows XP">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criteria operator="OR" comment="file checks">
                <criterion comment="Wmp.dll version is less than 10.0.0.4074" test_ref="oval:org.mitre.oval:tst:9758"/>
                <criterion comment="Wmpdxm.dll version is less than 10.0.0.4074" test_ref="oval:org.mitre.oval:tst:80893"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP x64, Windows Server 2003 x64">
              <criteria operator="OR" comment="OS Check">
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criteria operator="OR" comment="file checks">
                <criterion comment="the version of Wwmp.dll is less than 10.0.0.4006" test_ref="oval:org.mitre.oval:tst:10291"/>
                <criterion comment="Wwmpdxm.dll version is less than 10.0.0.4006" test_ref="oval:org.mitre.oval:tst:80694"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows Server 2003 x86">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criteria operator="OR" comment="file checks">
                <criterion comment="the version of Wmp.dll is less than 10.0.0.4006" test_ref="oval:org.mitre.oval:tst:9905"/>
                <criterion comment="Wmpdxm.dll version is less than 10.0.0.4006" test_ref="oval:org.mitre.oval:tst:80830"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows XP x86/x64 (KB973540)">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="file checks">
            <criterion comment="Wmp.dll version is less than 11.0.5721.5268" test_ref="oval:org.mitre.oval:tst:9769"/>
            <criterion comment="Wmpdxm.dll version is less than 11.0.5721.5268" test_ref="oval:org.mitre.oval:tst:80502"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista 32-bit/64-bit RTM (KB973540)">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR/LDR version check">
            <criterion comment="the version of Wmp.dll is less than 11.0.6000.6352" test_ref="oval:org.mitre.oval:tst:10628"/>
            <criterion comment="Wmpdxm.dll version is less than 11.0.6000.6352" test_ref="oval:org.mitre.oval:tst:80947"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="the version of Spwmp.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10025"/>
              <criteria operator="OR" comment="file checks">
                <criterion comment="the version of Wmp.dll is less than 11.0.6000.6511" test_ref="oval:org.mitre.oval:tst:10063"/>
                <criterion comment="Wmpdxm.dll version is less than 11.0.6000.6511" test_ref="oval:org.mitre.oval:tst:80516"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista 32/64-bit, Server 2008 32/64-bit (KB973540)">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR/LDR version check">
            <criterion comment="Wmp.dll version is less than 11.0.6001.7007" test_ref="oval:org.mitre.oval:tst:10523"/>
            <criterion comment="Wmpdxm.dll version is less than 11.0.6001.7007" test_ref="oval:org.mitre.oval:tst:80853"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="Spwmp.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10251"/>
              <criteria operator="OR" comment="file checks">
                <criterion comment="Wmp.dll version is less than 11.0.6001.7114" test_ref="oval:org.mitre.oval:tst:10759"/>
                <criterion comment="Wmpdxm.dll version is less than 11.0.6001.7114" test_ref="oval:org.mitre.oval:tst:80796"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista 32/64-bit, Server 2008 32/64-bit (KB973540)">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR/LDR version check">
            <criterion comment="Wmp.dll version is less than 11.0.6002.18065" test_ref="oval:org.mitre.oval:tst:10003"/>
            <criterion comment="Wmpdxm.dll version is less than 11.0.6002.18065" test_ref="oval:org.mitre.oval:tst:80462"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="Spwmp.dll version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10624"/>
              <criteria operator="OR" comment="file checks">
                <criterion comment="Wmp.dll version is less than 11.0.6002.22172" test_ref="oval:org.mitre.oval:tst:10699"/>
                <criterion comment="Wmpdxm.dll version is less than 11.0.6002.22172" test_ref="oval:org.mitre.oval:tst:80341"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows ATL Component on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of atl.dll is less than 3.0.9794.0" test_ref="oval:org.mitre.oval:tst:10738"/>
        </criteria>
        <criteria operator="AND" comment="Windows ATL Component on Windows XP, Server 2003, Vista, Server 2008">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of atl.dll is less than 3.5.2284.2" test_ref="oval:org.mitre.oval:tst:10563"/>
        </criteria>
        <criteria operator="AND" comment="DHTML Editing Component ActiveX Control on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of dhtmled.ocx is less than 6.1.0.9234" test_ref="oval:org.mitre.oval:tst:10669"/>
        </criteria>
        <criteria operator="AND" comment="DHTML Editing Component ActiveX Control on Windows XP or Server 2003 x86">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="the version of dhtmled.ocx is less than 6.1.0.9247" test_ref="oval:org.mitre.oval:tst:10482"/>
        </criteria>
        <criteria operator="AND" comment="DHTML Editing Component ActiveX Control on Windows XP or Server 2003 64-bit">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <criterion comment="the version of wdhtmled.ocx is less than 6.1.0.9247" test_ref="oval:org.mitre.oval:tst:10200"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft MSWebDVD ActiveX Control on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mswebdvd.dll version is less than 6.5.2600.3610" test_ref="oval:org.mitre.oval:tst:10763"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft MSWebDVD ActiveX Control on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mswebdvd.dll version is less than 6.5.2600.5857" test_ref="oval:org.mitre.oval:tst:10001"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft MSWebDVD ActiveX Control on Windows XP x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <criterion comment="the version of Mswebdvd.dll is less than 6.5.3790.4565" test_ref="oval:org.mitre.oval:tst:10694"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft MSWebDVD ActiveX Control on Server 2003 ia64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <criterion comment="the version of Mswebdvd.dll is less than 6.5.3790.3386" test_ref="oval:org.mitre.oval:tst:10733"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft HtmlInput Object ActiveX Control in Windows Vista">
          <criteria operator="OR" comment="OS Check for windows Vista X86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GRD/LDR version Check">
            <criterion comment="the version of Ehkeyctl.dll is less than 6.0.6000.16891" test_ref="oval:org.mitre.oval:tst:44448"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="the version of Ehkeyctl.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44368"/>
              <criterion comment="the version of Ehkeyctl.dll is less than 6.0.6000.21090" test_ref="oval:org.mitre.oval:tst:44201"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft HtmlInput Object ActiveX Control in Windows Vista">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR version Check">
            <criterion comment="the version of Ehkeyctl.dll is less than 6.0.6001.18295" test_ref="oval:org.mitre.oval:tst:44356"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="the version of Ehkeyctl.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44413"/>
              <criterion comment="the version of Ehkeyctl.dll is less than 6.0.6001.22476" test_ref="oval:org.mitre.oval:tst:44042"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft HtmlInput Object ActiveX Control in Windows Vista">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR version check">
            <criterion comment="the version of Ehkeyctl.dll is less than 6.0.6002.18072" test_ref="oval:org.mitre.oval:tst:44411"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="the version of Ehkeyctl.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:43878"/>
              <criterion comment="the version of Ehkeyctl.dll is less than 6.0.6002.22181" test_ref="oval:org.mitre.oval:tst:44323"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6500" version="3" class="inventory">
      <metadata>
        <title>Microsoft Visio Viewer 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visio_viewer:2002"/>
        <description>The application Microsoft Visio Viewer 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:52.175-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:09.736-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:52.037-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:48.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:48.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:14.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visio Viewer 2002 is installed" test_ref="oval:org.mitre.oval:tst:10895"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6420" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Visio Viewer 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visio_viewer:2003"/>
        <description>The application Microsoft Office Visio Viewer 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:52.391-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:56.118-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:40.873-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:48.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:48.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:13.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office Visio Viewer 2003 is installed" test_ref="oval:org.mitre.oval:tst:10709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6128" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Visio Viewer 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visio_viewer:2007"/>
        <description>The application Microsoft Office Visio Viewer 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:52.602-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:35.837-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:20.444-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:48.822-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:48.822-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:08.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office Visio Viewer 2007 is installed" test_ref="oval:org.mitre.oval:tst:10964"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:504" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 5.5 SP2 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express 5.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:5.5:sp2"/>
        <description>Microsoft Outlook Express 5.5 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.147-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.385-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:03.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Outlook Express 5.5 SP2 is installed" test_ref="oval:org.mitre.oval:tst:1514"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:488" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 6 SP1 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express 6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.00.2800.1106"/>
        <description>Microsoft Outlook Express 6 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:58.863-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:38.525-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:03.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Outlook Express 6 SP1 is installed" test_ref="oval:org.mitre.oval:tst:1355"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:325" version="7" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 5.01 SP4 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:5.00.3700.1000"/>
        <description>The application Microsoft Internet Explorer 5.01 SP4 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:20.990-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:38.551-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version. Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.660-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:18.349-05:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:39.060-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:23.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:50.275-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.934-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:325 - Added MS IE5 to inventory" date="2015-05-12T14:23:00.788-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-12T14:25:53.055-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:23.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2794"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:208" version="8" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 6.0 for Windows XP/2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.0"/>
        <description>Microsoft Outlook Express 6.0 for Windows XP/2003 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-03T12:32:22">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-07-03T14:04:49.139-04:00">DRAFT</status_change>
            <status_change date="2007-07-18T15:57:53.037-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:15.591-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:51.618-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:31.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-12-27T19:58:09.275-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:19.196-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:208 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:18.675-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:15.525-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:59.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18961" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook 2007 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Outlook 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook:2007:sp1"/>
        <description>Microsoft Outlook 2007 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T10:01:48.772-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:32.108-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:47.979-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Outlook 2007 is installed" definition_ref="oval:org.mitre.oval:def:5352"/>
        <criterion comment="Check if the version of outlook.exe is greater than or equal to 12.0.6212.1000" test_ref="oval:org.mitre.oval:tst:86652"/>
        <criterion comment="Check if the version of Outlook.exe is less than 12.0.6423.1000" test_ref="oval:org.mitre.oval:tst:86578"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18844" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook 2007 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Outlook 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook:2007:sp2"/>
        <description>Microsoft Outlook 2007 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T10:01:53.791-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:17.253-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:34.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Outlook 2007 is installed" definition_ref="oval:org.mitre.oval:def:5352"/>
        <criterion comment="Check if the version of Outlook.exe is greater than or equal to 12.0.6423.1000" test_ref="oval:org.mitre.oval:tst:86654"/>
        <criterion comment="Check if the version of outlook.exe is less than 12.0.6607.1000" test_ref="oval:org.mitre.oval:tst:86688"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6710" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird, Firefox and Seamonkey Cross Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306"/>
        <description>The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:08:00.671-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:14.668-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:06.521-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:59.883-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:50.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:38.204-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:01.796-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6710 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:11.722-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:49.126-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6710 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:35.206-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:30.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:44.854-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6710 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:20.878-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:42.953-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:17.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:41.230-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:15.983-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6709" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Marquee Event 'SelectionController' Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1399"/>
        <description>WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during a selection change on a form input element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:47.925-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:05.208-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:08.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6709 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:19.811-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:56.831-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:32.710-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:35.706-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:05.627-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:15.801-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:55.296-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.521-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6708" version="19" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox, Thunderbird and Seamonkey Denial of Service and arbitrary code execution Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0773"/>
        <description>The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:04:09.670-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:14.291-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:06.016-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5010 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:44.372-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:59.942-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:58.796-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:50.174-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:01:36.910-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:01.295-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6708 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:47.611-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:48.961-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6708 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:39.312-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:30.464-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:44.598-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6708 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:20.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:42.652-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:17.368-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:15:40.975-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:15.765-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.20" test_ref="oval:org.mitre.oval:tst:114906"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.15" test_ref="oval:org.mitre.oval:tst:99439"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.6" test_ref="oval:org.mitre.oval:tst:9992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6707" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 PICT Image Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2837"/>
        <description>Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:57.884-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:21.923-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:05.677-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:11.769-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:35.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:39.411-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:18.317-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6707 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:57.925-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:40.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6705" version="9" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in IrfanView via a crafted PSD image with RLE compression</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>IrfanView</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1509"/>
        <description>IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-19T03:34:03">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2010-05-19T10:10:23.648-04:00">DRAFT</status_change>
            <status_change date="2010-06-07T04:00:05.349-04:00">INTERIM</status_change>
            <status_change date="2010-06-28T04:00:04.833-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:409 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:56.520-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:34.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:46.700-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:29.734-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:23.493-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:20.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="IrfanView is installed" definition_ref="oval:org.mitre.oval:def:7162"/>
        <criteria operator="OR">
          <criterion comment="IrfanView display version is less than 4.27" test_ref="oval:org.mitre.oval:tst:11566"/>
          <criterion comment="IrfanView binary version is less than 4.27" test_ref="oval:org.mitre.oval:tst:11511"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6704" version="3" class="vulnerability">
      <metadata>
        <title>AOL SuperBuddy ActiveX Control Remote Code Execution Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>AOL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3658"/>
        <description>Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:51.501-05:00">DRAFT</status_change>
            <modified comment="Removed the trailing backspace on obj:6527 to standardize with the rest of the OVAL Repository." date="2009-12-03T17:11:00.816-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-12-21T04:01:17.468-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:19.490-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:813 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:52.710-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:34.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="AOL is installed" definition_ref="oval:org.mitre.oval:def:6607"/>
        <criterion comment="AOL version is less or equal to 9.5.0.1" test_ref="oval:org.mitre.oval:tst:11076"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6607" version="5" class="inventory">
      <metadata>
        <title>AOL is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>AOL</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:aol:internet_software"/>
        <description>The application AOL is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:51.193-05:00">DRAFT</status_change>
            <modified comment="Removed the trailing backspace on obj:7089 to standardize with the rest of the OVAL Repository." date="2009-12-03T16:34:00.844-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-12-21T04:01:13.131-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:05.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6607 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:39.391-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:24.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6607 - Typo Corrections" date="2014-05-22T11:03:00.270-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:06:06.236-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:47.972-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Relevant version of Windows is installed">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
        </criteria>
        <criterion comment="AOL is installed" test_ref="oval:org.mitre.oval:tst:10242"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6703" version="3" class="vulnerability">
      <metadata>
        <title>Array index error vulnerability in RealNetworks RealPlayer 11.0 through 11.1</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2996" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2996"/>
        <description>Array index error in RealNetworks RealPlayer 11.0 through 11.1 on Windows allows remote attackers to execute arbitrary code via a malformed header in a RealMedia .IVR file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:25.802-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:08.519-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:03.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="AND">
          <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
          <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6696" version="6" class="vulnerability">
      <metadata>
        <title>Windows MFC Document Title Updating Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3227" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3227"/>
        <description>Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:52.847-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:37:00.947-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:05.350-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:08.689-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:44.681-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:44.681-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:20.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6151" test_ref="oval:org.mitre.oval:tst:11595"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6695" version="7" class="vulnerability">
      <metadata>
        <title>Word Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3217" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3217"/>
        <description>Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:49:34.236-04:00">DRAFT</status_change>
            <modified comment="Added the comments on the non-top level &lt;criteria> tags." date="2010-11-03T13:20:00.790-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-11-22T04:00:04.786-05:00">INTERIM</status_change>
            <status_change date="2010-12-13T04:00:08.235-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6498 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:39.767-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:10.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6866.0" test_ref="oval:org.mitre.oval:tst:11360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6694" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Unspecified Clickjacking Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1867"/>
        <description>Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:32.402-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:28.449-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:42:00.495-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:07.234-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:50.184-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:17.869-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:10:03.080-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:11.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:22.143-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.846-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6694 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:10.179-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:15.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6694 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:14.115-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:56.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123016"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:122750"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6693" version="5" class="vulnerability">
      <metadata>
        <title>Oracle MySQL 'COM_FIELD_LIST' Command Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>MySQL Server 5.0</product>
          <product>MySQL Server 5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1850" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1850"/>
        <description>Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:42.709-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:04.205-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:08.250-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7196 - &quot;\&quot; was removed before &quot;_&quot; and regular expressions were simplified" date="2013-10-17T12:07:00.149-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:08:37.967-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:15.123-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.0 is installed" definition_ref="oval:org.mitre.oval:def:8282"/>
          <criterion comment="MySQL Server 5.0 version is less than 5.0.91" test_ref="oval:org.mitre.oval:tst:27183"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="MySQL 5.1 is installed" definition_ref="oval:org.mitre.oval:def:8297"/>
          <criterion comment="MySQL Server 5.1 version is less than 5.1.47" test_ref="oval:org.mitre.oval:tst:27571"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8282" version="9" class="inventory">
      <metadata>
        <title>MySQL 5.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>MySQL Server 5.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:mysql:mysql:5.0"/>
        <description>MySQL Server 5.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-22T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-27T13:49:17.724-05:00">DRAFT</status_change>
            <status_change date="2010-02-15T04:00:08.668-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:14.262-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:349 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:49.357-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:02:49.585-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:911 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:13.720-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:31.338-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11786 - new inventory and platforms for MySQL 5.6" date="2014-09-11T08:17:00.634-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-11T08:19:27.923-04:00">INTERIM</status_change>
            <status_change date="2014-09-29T04:00:27.722-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11992 - Added 32-bit windows view" date="2014-10-24T13:20:00.601-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:20:47.419-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:36.551-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MySQL 5.0 is installed" test_ref="oval:org.mitre.oval:tst:20481"/>
        <criterion comment="mysqld.exe or mysqld-nt.exe exists" test_ref="oval:org.mitre.oval:tst:21031"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6691" version="13" class="vulnerability">
      <metadata>
        <title>Google Chrome WebKit Variable Casting Weakness Malformed SVG Document Handling Unspecified Issue</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1822"/>
        <description>WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-07T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-10-08T16:39:36.250-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:17.536-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:31.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7143 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:53:32.281-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:06.762-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:49.231-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:51.331-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:21:50.902-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:57.222-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:06:28.303-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:49.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:29:42.495-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:38.636-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Google Chrome version is less than 6.0.472.62" test_ref="oval:org.mitre.oval:tst:11067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6686" version="9" class="vulnerability">
      <metadata>
        <title>HTML Element Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1260"/>
        <description>The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:18.494-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:45.183-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:07.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:05.498-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:51.313-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.712-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.712-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:20.184-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6686 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.936-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:17.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6684" version="3" class="vulnerability">
      <metadata>
        <title>RTSP Use After Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3225" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3225"/>
        <description>Use-after-free vulnerability in the Media Player Network Sharing Service in Microsoft Windows Vista SP1 and SP2 and Windows 7 allows remote attackers to execute arbitrary code via a crafted Real Time Streaming Protocol (RTSP) packet, aka "RTSP Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:59.055-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:03.798-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:13.552-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 sp1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmpmde.dll is less than 11.0.6001.7009" test_ref="oval:org.mitre.oval:tst:11826"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmpmde.dll is greater than or equal to 11.0.6001.7100" test_ref="oval:org.mitre.oval:tst:11418"/>
              <criterion comment="the version of Wmpmde.dll is less than 11.0.6001.7117" test_ref="oval:org.mitre.oval:tst:11610"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 sp2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmpmde.dll is less than 11.0.6002.18297" test_ref="oval:org.mitre.oval:tst:11417"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmpmde.dll is greater than or equal to 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11397"/>
              <criterion comment="the version of Wmpmde.dll is less than 11.0.6002.22471" test_ref="oval:org.mitre.oval:tst:11377"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmpmde.dll is less than 12.0.7600.16661" test_ref="oval:org.mitre.oval:tst:11375"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmpmde.dll is greater than or equal to 12.0.7600.20000" test_ref="oval:org.mitre.oval:tst:11406"/>
              <criterion comment="the version of Wmpmde.dll is less than 12.0.7600.20787" test_ref="oval:org.mitre.oval:tst:11371"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6677" version="19" class="vulnerability">
      <metadata>
        <title>toStaticHTML Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Office InfoPath 2003</product>
          <product>Microsoft Office InfoPath 2007</product>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Windows SharePoint Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1257"/>
        <description>Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:17.213-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:44.338-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:06.252-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:08.094-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:50.420-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.040-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.040-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:19.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:21.638-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:27.896-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6677 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:49.942-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:34.985-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:157 - New defs for Office 2010 SP2 and multiple platform updates" date="2013-08-14T09:59:00.133-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-08-14T10:04:57.220-04:00">INTERIM</status_change>
            <status_change date="2013-09-02T04:05:47.938-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:39.348-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:13.508-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:00.171-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:20.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6677 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:57.421-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:16.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Windows XP, Server 2003">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Windows XP, Server 2003">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Windows Vista, Server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="Windows 7, Server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="Windows 7, Server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office InfoPath 2003">
          <extend_definition comment="Microsoft InfoPath 2003 is installed" definition_ref="oval:org.mitre.oval:def:7304"/>
          <criterion comment="the version of Infopath.exe is less than 11.0.8233.0" test_ref="oval:org.mitre.oval:tst:27681"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office InfoPath 2007">
          <extend_definition comment="Microsoft InfoPath 2007 is installed" definition_ref="oval:org.mitre.oval:def:7345"/>
          <criterion comment="infopath.exe version is less than 12.0.6529.5000" test_ref="oval:org.mitre.oval:tst:27644"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2007">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criteria operator="OR" comment="Osafehtm.dll or Onetutil.dll">
            <criterion comment="the version of Osafehtm.dll is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:27581"/>
            <criterion comment="the version of Onetutil.dll is less than 12.0.6524.5003" test_ref="oval:org.mitre.oval:tst:27356"/>
          </criteria>
        </criteria>
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criteria operator="OR" comment="Windows Server 2003 32-bit or Windows Server 2003 64-bit">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6535.5003" test_ref="oval:org.mitre.oval:tst:27741"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7304" version="7" class="inventory">
      <metadata>
        <title>Microsoft InfoPath 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft InfoPath 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:infopath:2003"/>
        <description>The application Microsoft InfoPath 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:15.159-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:41.996-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:40.169-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.056-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.056-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:53.761-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12292 - Updating pre-Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:55:00.075-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:57:24.838-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:26.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="InfoPath 2003 is installed" test_ref="oval:org.mitre.oval:tst:27539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6674" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Mouse Pointer Display Issue May Let Remote Users Conduct Clickjacking Attacks</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0522"/>
        <description>Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T03:25:55">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:31.345-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:16.434-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:11.496-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7075 - Changed to match Flash Player ActiveX as well as the Plugin." date="2010-01-14T21:25:00.737-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-14T21:26:51.340-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:28.130-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11159 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:18.685-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:17.452-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:48.881-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:10.851-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:06.816-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.776-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6674 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:18.394-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:15.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6674 - Added criteria for Adobe air." date="2015-02-26T19:32:00.874-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:35:36.279-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:58.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Flash Player section">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:10855"/>
            <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
              <criterion comment="Adobe Flash Player version installed on the system is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:11224"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:11159"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Flash.ocx section">
          <criterion comment="Determine if the version of Flash.ocx is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:122849"/>
          <criteria operator="AND" comment="Vulnerable version of Flash.ocx">
            <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:122989"/>
          </criteria>
        </criteria>
        <criteria comment="Adobe AIR section">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if the version of Adobe AIR is less than or equal 1.5" test_ref="oval:org.mitre.oval:tst:138162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6673" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 M-JPEG Encoded Movie Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0517" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0517"/>
        <description>Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with M-JPEG encoding, which causes QuickTime to calculate a buffer size using height and width fields, but to use a different field to control the length of a copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:56.727-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:21.713-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:05.107-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:09.227-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:34.231-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:35.754-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:16.977-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6673 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:58.633-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:40.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6668" version="3" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability via a Trojan horse dwmapi.dll in TechSmith SnagIt version from 8.2.1 to 10.0.0(build 788)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>TechSmith SnagIt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3130" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3130"/>
        <description>Untrusted search path vulnerability in TechSmith SnagIt 10 (Build 788) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a snag, snagcc, or snagprof file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-28T12:42:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:21.349-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:09.716-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:03.347-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="TechSmith SnagIt is installed" definition_ref="oval:org.mitre.oval:def:7558"/>
        <criteria operator="AND">
          <criterion comment="Check whether TechSmith SnagIt is greater than or equal to 8.2.1.205" test_ref="oval:org.mitre.oval:tst:11213"/>
          <criterion comment="Check whether TechSmith SnagIt less than or equal to 10.0.0.788" test_ref="oval:org.mitre.oval:tst:11457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7558" version="5" class="inventory">
      <metadata>
        <title>TechSmith SnagIt is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>TechSmith SnagIt</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:techsmith:snagit"/>
        <description>TechSmith Snagit is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-28T12:42:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-30T13:26:20.884-04:00">DRAFT</status_change>
            <status_change date="2010-10-18T04:00:12.608-04:00">INTERIM</status_change>
            <status_change date="2010-11-08T04:00:22.271-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7558 - modified inventories for Microsoft Expression Design." date="2013-07-05T09:53:00.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:58:03.422-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:14.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if TechSmith SnagIt is installed" test_ref="oval:org.mitre.oval:tst:11380"/>
        <criterion comment="The registry key that holds the location of TechSmith SnagIt exists" test_ref="oval:org.mitre.oval:tst:81684"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6663" version="13" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player ActiveX Control Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3951" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3951"/>
        <description>Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:35.189-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:27.812-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:02.702-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation from &quot;less than&quot; to &quot;less than or equal&quot; for ste:4861" date="2010-03-22T10:43:00.931-04:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2010-03-22T10:44:09.659-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:21.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:40.665-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:16.565-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:57.066-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:10.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:08.395-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.678-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11528 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:20.674-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:15.118-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6663 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:13.907-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:56.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.3" test_ref="oval:org.mitre.oval:tst:11645"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version installed on the system is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:11528"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 10.0.42.34" test_ref="oval:org.mitre.oval:tst:122097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6662" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Settings Manager May Let Remote Users Conduct Clickjacking Attacks</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0114"/>
        <description>Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T03:25:55">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:31.784-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:16.123-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:10.355-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7075 - Changed to match Flash Player ActiveX as well as the Plugin." date="2010-01-14T21:25:00.737-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-14T21:26:51.420-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:27.488-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11159 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:19.166-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:16.168-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:56.621-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:09.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:08.320-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.606-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11224 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:29.963-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:14.939-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6662 - Added criteria for Adobe air." date="2015-02-26T19:32:00.874-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:35:36.877-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:58.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Flash Player section">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:10855"/>
            <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
              <criterion comment="Adobe Flash Player version installed on the system is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:11224"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:11159"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Flash.ocx section">
          <criterion comment="Determine if the version of Flash.ocx is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:122849"/>
          <criteria operator="AND" comment="Vulnerable version of Flash.ocx">
            <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:122989"/>
          </criteria>
        </criteria>
        <criteria comment="Adobe AIR section">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if the version of Adobe AIR is less than or equal 1.5" test_ref="oval:org.mitre.oval:tst:138162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6660" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Loader Object Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1864"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:31.614-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:27.159-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:42:00.727-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:06.790-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:48.939-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:15.718-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:08:55.709-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:09.357-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:08.156-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.531-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6660 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:31.906-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:14.714-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6660 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:16.581-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:56.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of  Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123016"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:122750"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6656" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Malformed URL Handling Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0544" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0544"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to a malformed URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:51.609-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:03.911-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:05.850-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6656 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:08.366-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:56.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:25.077-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:33.814-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:54.498-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:12.770-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:57.845-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.434-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6654" version="13" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Google Chrome before 7.0.517.41</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Google Chrome</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4042"/>
        <description>Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "stale elements."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T17:24:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:41.286-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:29.125-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:44.458-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:7449 - The attached file replaces existing Chrome objects with new objects containing the set of the existing object, which is correct for individual installs, and the registry key used by the all users installer." date="2011-10-17T12:47:00.319-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T12:52:48.947-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:06.452-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15888 - Updated a set of Chrome Tests to use the Version registry key, as opposed to the DisplayName key." date="2012-02-06T11:48:00.676-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-06T11:58:23.689-05:00">INTERIM</status_change>
            <status_change date="2012-02-27T04:04:50.892-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - Make registry key checking faster." date="2012-03-28T14:11:00.591-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-03-28T14:18:48.955-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:56.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16406 - Added windows_view behavior to Google Chrome on 64-bit Windows objects." date="2012-10-05T15:50:00.984-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-10-05T16:03:06.779-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:48.700-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15257 - var_check=&quot;at least one&quot; added to obj:15257" date="2013-07-24T13:14:00.080-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-24T13:25:52.750-04:00">INTERIM</status_change>
            <status_change date="2013-08-12T04:09:38.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Google Chrome is installed" definition_ref="oval:org.mitre.oval:def:11914"/>
        <criterion comment="Check if the version of Google Chrome is less than 7.0.517.41" test_ref="oval:org.mitre.oval:tst:20627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6653" version="13" class="vulnerability">
      <metadata>
        <title>Windows Media Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2745"/>
        <description>Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitrary code via crafted media content referenced in an HTML document, aka "Windows Media Player Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:20.616-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:28.287-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:43.626-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.494-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.494-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:17.851-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6653 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:53:00.179-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:04.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10251 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-30T10:26:30.362-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:17.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6653 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:12.123-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:16.531-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20961 - MS bulletins for the month of June 2015" date="2015-06-18T10:14:00.489-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-18T10:17:12.835-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:46.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Media Player 9 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.4510" test_ref="oval:org.mitre.oval:tst:21458"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4081" test_ref="oval:org.mitre.oval:tst:21227"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP (x64-bit) or Windows Server 2003 (x64-bit)">
          <criteria operator="OR" comment="Windows XP (x64-bit) or Windows Server 2003 (x64-bit)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wwmp.dll is less than 10.0.0.4008" test_ref="oval:org.mitre.oval:tst:20961"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on windows server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4008" test_ref="oval:org.mitre.oval:tst:21417"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows XP x86 or windows XP (x64-bit)">
          <criteria operator="OR" comment="Windows XP x86 or windows XP (x64-bit)">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion comment="the version of Wmp.dll is less than 11.0.5721.5280" test_ref="oval:org.mitre.oval:tst:21412"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista/Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6001.7010" test_ref="oval:org.mitre.oval:tst:21303"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spwmp.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10251"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6001.7118" test_ref="oval:org.mitre.oval:tst:21416"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista /Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6002.18311" test_ref="oval:org.mitre.oval:tst:21253"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Wmp.dll is greater than or equal 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21257"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6002.22486" test_ref="oval:org.mitre.oval:tst:21471"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 12 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Windows Media Player v12 is installed." definition_ref="oval:org.mitre.oval:def:7384"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Wmp.dll is less than 12.0.7600.16667" test_ref="oval:org.mitre.oval:tst:20189"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmp.dll is greater than or equal 12.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20141"/>
              <criterion comment="The version of Wmp.dll is less than 12.0.7600.20792" test_ref="oval:org.mitre.oval:tst:20478"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6652" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1289" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1289"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1290, and CVE-2010-1291.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:47.699-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:24.155-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:04.149-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:07.850-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:32.473-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6651" version="3" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
          <product>RealPlayer SP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3000" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3000"/>
        <description>Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:26.071-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:08.177-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:03.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="RealPlayer or RealPlayer SP is installed on the system" definition_ref="oval:org.mitre.oval:def:7330"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer SP is greater than or equal to 1.0" test_ref="oval:org.mitre.oval:tst:11442"/>
            <criterion comment="Check if the version of RealPlayer SP is less than 1.1.5" test_ref="oval:org.mitre.oval:tst:11165"/>
          </criteria>
          <criteria operator="AND">
            <criterion comment="Check if the version of RealPlayer is greater than or equal to 11.0" test_ref="oval:org.mitre.oval:tst:11392"/>
            <criterion comment="Check if the version of RealPlayer is less than or equal to 11.1" test_ref="oval:org.mitre.oval:tst:11291"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7330" version="3" class="inventory">
      <metadata>
        <title>RealPlayer or RealPlayer SP is installed on the system</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>RealPlayer</product>
          <product>RealPlayer SP</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:realnetworks:realplayer"/>
        <reference source="CPE" ref_id="cpe:/a:realnetworks:realplayer_sp"/>
        <description>RealPlayer or RealPlayer SP is installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-22T01:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-09-22T22:05:24.253-04:00">DRAFT</status_change>
            <status_change date="2010-10-11T04:00:15.179-04:00">INTERIM</status_change>
            <status_change date="2010-11-01T04:00:11.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if RealPlayer or RealPlayer SP is installed" test_ref="oval:org.mitre.oval:tst:11273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6650" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow vulnerability in kavfm.sys in Kingsoft Antivirus 2010.7.30.201 and earlier</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Kingsoft Antivirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3396"/>
        <description>Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-22T18:45:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:08.637-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:27.886-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:43.283-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Kingsoft Antivirus is installed" definition_ref="oval:org.mitre.oval:def:6932"/>
        <criterion comment="Check if the version of kavfm.sys in Kingsoft Antivirus is less than or equal to 2010.7.30.201" test_ref="oval:org.mitre.oval:tst:19977"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6932" version="3" class="inventory">
      <metadata>
        <title>Kingsoft Antivirus is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Kingsoft Antivirus</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:kingsoftsecurity:kingsoft_antivirus"/>
        <description>Kingsoft Antivirus is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-22T18:45:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:08.123-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:36.902-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.331-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Kingsoft Antivirus is installed" test_ref="oval:org.mitre.oval:tst:20507"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6649" version="11" class="vulnerability">
      <metadata>
        <title>WebKit Dragging or Pasting Cross Domain Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1389"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) paste or (2) drag-and-drop operation for a selection.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-06-09T13:33:45.854-04:00">DRAFT</status_change>
            <status_change date="2010-06-28T04:00:03.505-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:05.610-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6649 - Added criterion to handle lower versions of the product, removed OS tests" date="2011-02-22T12:52:00.544-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:55:13.388-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:56.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:28.230-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:33.418-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:59.145-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:11.877-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15442 - oval:org.mitre.oval:obj:15442. var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-12-13T11:08:00.276-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-13T11:09:51.935-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:01:02.291-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criteria operator="OR" comment="Check if Apple Safari version is less than 5.33.16.0">
          <criterion comment="Check if Apple Safari version is less than 5.33.16.0 (From StartMenuInternet)" test_ref="oval:org.mitre.oval:tst:42105"/>
          <criterion comment="Apple Safari version is less than 5.33.16.0" test_ref="oval:org.mitre.oval:tst:27458"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6648" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player and AIR Sandbox Bypass Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1870"/>
        <description>Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local sandbox vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-14T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-14T21:37:33.282-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:26.795-05:00">INTERIM</status_change>
            <modified comment="Correcting reversed tests for v9 and v10" date="2010-02-15T10:35:00.330-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T04:00:06.380-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11628 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:27:48.550-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:15.298-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:23.149-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7160 - Adobe Flash Player vulnerabilities 2013" date="2013-06-14T10:23:00.475-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-01T04:02:08.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:13.181-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.447-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6648 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:16.208-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:14.548-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6648 - Added extended definitions for Adobe Flash Player and ActiveX Control" date="2015-07-13T20:38:00.177-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:41:06.685-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:55.954-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable version of Adobe AIR">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Adobe AIR version is less than 1.5.2" test_ref="oval:org.mitre.oval:tst:11755"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
          <extend_definition comment="Adobe Flash Player 10 is installed" definition_ref="oval:org.mitre.oval:def:7610"/>
          <criterion comment="Adobe Flash Player version is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:11243"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 9">
          <extend_definition comment="Adobe Flash Player 9 is installed" definition_ref="oval:org.mitre.oval:def:7402"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:11628"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criteria operator="OR" comment="Flash.ocx versions section">
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.32.18" test_ref="oval:org.mitre.oval:tst:123016"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 9.0.246.0" test_ref="oval:org.mitre.oval:tst:122750"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6646" version="17" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird, Firefox and Seamonkey Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303"/>
        <description>The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:06:48.009-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:13.856-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:05.591-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:30.913-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:49.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T18:00:15.910-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:12:00.767-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6646 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:10.887-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:48.619-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6646 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:36.696-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:30.293-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6768 - Changed to registry default value of HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird" date="2014-06-06T16:25:00.703-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2014-06-06T16:27:05.769-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6646 - Fixed vulnerability detection; replaced registry tests with file tests" date="2014-06-13T17:43:00.534-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:19.898-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30168 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:01.432-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:16.325-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30018 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:14:54.076-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:14.306-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check Mozilla Thunderbird version">
          <extend_definition comment="Mozilla Thunderbird Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22093"/>
          <criterion comment="Thunderbird version is less than or equal to 2.0.0.21" test_ref="oval:org.mitre.oval:tst:114271"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Seamonkey version">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Seamonkey version is less than or equal to 1.1.16" test_ref="oval:org.mitre.oval:tst:114285"/>
        </criteria>
        <criteria operator="AND" comment="Check Mozilla Firefox version">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6645" version="7" class="vulnerability">
      <metadata>
        <title>Vulnerability in pl\php ADD-ON in PostgreSQL version less than or equal to 9.0</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PostgreSQL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3781"/>
        <description>The PL/php add-on 1.4 and earlier for PostgreSQL does not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, a related issue to CVE-2010-3433.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-21T11:57:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-21T15:40:27.851-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:02.407-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:12.963-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6960 - var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-10-29T16:13:00.745-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-29T16:15:34.968-04:00">INTERIM</status_change>
            <status_change date="2013-11-14T10:21:30.532-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11725 - Added 32-bit branch and corrected check" date="2015-03-06T14:46:00.120-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-06T14:48:45.054-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Check if PostgreSQL version is 7.4.x, 8.0.x,8.1.x, 8.2.x, 8.3.x, 8.4.x, 9.0.x series">
          <criteria operator="AND" comment="Check if PostgreSQL version is 7.4.x before 7.4.30">
            <criterion comment="Check if PostgreSQL version  is 7.4.x series" test_ref="oval:org.mitre.oval:tst:11631"/>
            <criterion comment="Check if PostgreSQL version is less than 7.4.30" test_ref="oval:org.mitre.oval:tst:11658"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.0.x before 8.0.26">
            <criterion comment="Check if PostgreSQL version is less than  8.0.26" test_ref="oval:org.mitre.oval:tst:11930"/>
            <criterion comment="Check if PostgreSQL version is 8.0.x series" test_ref="oval:org.mitre.oval:tst:11909"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 9.0.x before 9.0.1">
            <criterion comment="Check if PostgreSQL version is 9.0.x series" test_ref="oval:org.mitre.oval:tst:11640"/>
            <criterion comment="Check if PostgreSQL version is less than  9.0.1" test_ref="oval:org.mitre.oval:tst:11717"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.1.x before 8.1.22">
            <criterion comment="Check if PostgreSQL version is less than  8.1.22" test_ref="oval:org.mitre.oval:tst:11673"/>
            <criterion comment="Check if PostgreSQL version is 8.1.x series" test_ref="oval:org.mitre.oval:tst:11725"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.2.x before 8.2.18">
            <criterion comment="Check if PostgreSQL version is less than  8.2.18" test_ref="oval:org.mitre.oval:tst:11680"/>
            <criterion comment="Check if PostgreSQL version is 8.2.x series" test_ref="oval:org.mitre.oval:tst:11744"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.3.x before 8.3.12">
            <criterion comment="Check if PostgreSQL version is less than  8.3.12" test_ref="oval:org.mitre.oval:tst:11689"/>
            <criterion comment="Check if PostgreSQL version is 8.3.x series" test_ref="oval:org.mitre.oval:tst:11778"/>
          </criteria>
          <criteria operator="AND" comment="Check if PostgreSQL version is 8.4.x before 8.4.5">
            <criterion comment="Check if PostgreSQL version is less than  8.4.5" test_ref="oval:org.mitre.oval:tst:11766"/>
            <criterion comment="Check if PostgreSQL version is 8.4.x series" test_ref="oval:org.mitre.oval:tst:11913"/>
          </criteria>
        </criteria>
        <extend_definition comment="PostgreSQL is installed" definition_ref="oval:org.mitre.oval:def:6785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6785" version="7" class="inventory">
      <metadata>
        <title>PostgreSQL is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PostgreSQL</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:postgresql:postgresql"/>
        <description>PostgreSQL is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-21T11:57:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-21T15:40:25.837-04:00">DRAFT</status_change>
            <status_change date="2010-11-08T04:00:05.884-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:14.964-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11591 - Updated tst:11591." date="2014-11-13T08:14:00.643-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-13T08:17:06.482-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:01:06.487-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7558 - Added 32-bit branch and corrected check" date="2015-03-06T14:46:00.120-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-06T14:48:45.475-05:00">INTERIM</status_change>
            <status_change date="2015-03-23T04:02:32.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if PostgreSQL is installed" test_ref="oval:org.mitre.oval:tst:11591"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6638" version="5" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player Multiple Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1284"/>
        <description>Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-12T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-05-14T10:00:46.884-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:23.769-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:03.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:07.367-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:32.263-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="Adobe Shockwave Player version is less than 11.5.7.609" test_ref="oval:org.mitre.oval:tst:11787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6634" version="5" class="vulnerability">
      <metadata>
        <title>Excel Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1249" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1249"/>
        <description>Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:52.495-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:41.555-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:04.622-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:05.766-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:08.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6630" version="5" class="vulnerability">
      <metadata>
        <title>Excel Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1247" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1247"/>
        <description>Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:52.915-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:40.974-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:03.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:25:06.114-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:08.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Excel 2002">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6862.0" test_ref="oval:org.mitre.oval:tst:27600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6626" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime Before 7.6.6 H.263 Encoded Movie Handling Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0062"/>
        <description>Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-06T10:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-04-07T15:52:57.412-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:21.131-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:04.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:04.262-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:33.130-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:41.375-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:14.912-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6626 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:18.551-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:39.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.6 (7.66.71.0)" test_ref="oval:org.mitre.oval:tst:11461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6593" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Invalid Object Reference Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0520" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0520"/>
        <description>Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T03:25:55">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:30.947-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:12.141-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:02:03.538-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7075 - Changed to match Flash Player ActiveX as well as the Plugin." date="2010-01-14T21:25:00.737-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-14T21:26:50.957-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:26.469-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11159 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:19.525-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:14.114-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:59.941-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:08.345-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:21.524-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.366-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6593 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:28.870-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:14.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6593 - Added criteria for Adobe air." date="2015-02-26T19:32:00.874-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:35:36.481-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:57.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Flash Player section">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:10855"/>
            <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
              <criterion comment="Adobe Flash Player version installed on the system is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:11224"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:11159"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Flash.ocx section">
          <criterion comment="Determine if the version of Flash.ocx is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:122849"/>
          <criteria operator="AND" comment="Vulnerable version of Flash.ocx">
            <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:122989"/>
          </criteria>
        </criteria>
        <criteria comment="Adobe AIR section">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if the version of Adobe AIR is less than or equal 1.5" test_ref="oval:org.mitre.oval:tst:138162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6582" version="9" class="vulnerability">
      <metadata>
        <title>Vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4 to cause a denial of service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379"/>
        <description>Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:22.258-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:21.997-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:18.003-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:47.150-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:48.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6582 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:29.741-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:17.073-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:18.953-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:13.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6580" version="9" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 to cause a denial of service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:22.056-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:21.361-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:17.667-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:53.151-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:48.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6580 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:27.922-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:16.966-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:19.228-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:13.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Mozilla Firefox Mainline version is 3.0.x to 3.0.14" test_ref="oval:org.mitre.oval:tst:120713"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6574" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption error in Opera before 10.01 when processing malformed domain names</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3831"/>
        <description>Opera before 10.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted domain name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-24T10:15:45.529">
              <contributor organization="SecPod Technologies">Nikita MR</contributor>
            </submitted>
            <status_change date="2009-11-24T14:51:39.472-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:17.364-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:54.341-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:54.419-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:26.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6574 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:12.316-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:48.695-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.01" test_ref="oval:org.mitre.oval:tst:11074"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6570" version="8" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-3674)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3674"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:12.102-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:37.834-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:10.742-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:37:00.237-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:37:45.242-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:19.874-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:50.025-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:50.025-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:16.549-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6578 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:19.120-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:29.911-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6570 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:45.998-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:15.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18854" test_ref="oval:org.mitre.oval:tst:10325"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22945" test_ref="oval:org.mitre.oval:tst:11217"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18865" test_ref="oval:org.mitre.oval:tst:11230"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22956" test_ref="oval:org.mitre.oval:tst:11290"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:21026"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16466" test_ref="oval:org.mitre.oval:tst:11033"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20579" test_ref="oval:org.mitre.oval:tst:10797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6565" version="9" class="vulnerability">
      <metadata>
        <title>Vulnerability in the XPCVariant::VariantDataToJS function in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374"/>
        <description>The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:23.090-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:20.787-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:16.830-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:16.275-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:48.120-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6565 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:40.167-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:16.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:12.018-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:13.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Mozilla Firefox Mainline version is 3.0.x to 3.0.14" test_ref="oval:org.mitre.oval:tst:120713"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6555" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Office Word File Information Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Word 2002</product>
          <product>Microsoft Word 2003</product>
          <product>Microsoft Office Word Viewer 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3135"/>
        <description>Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:39.992-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:58.003-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:09.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1517 - In obj:1517 for Office Word Viewer is updated by adding new variable and object to make it work. Earlier obj:1517 was referring to OfficeWord object path" date="2011-07-18T15:27:00.494-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-18T15:28:20.256-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:49.879-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6394 - Updating Microsoft Word registry locations." date="2012-05-10T14:37:00.794-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:51:16.652-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:08.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15263 - added new criteria and 32 bit checks." date="2013-01-31T09:01:00.731-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-31T09:03:28.515-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:32.259-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2002">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of Winword.exe is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11075"/>
        </criteria>
        <criteria operator="AND" comment="Word 2003">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of Winword.exe is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:10328"/>
        </criteria>
        <criteria operator="AND" comment="Word Viewer 2003">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of Wordview.exe is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:10942"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6554" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allows attackers to cause a DoS via unspecified vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2995" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2995"/>
        <description>Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:38.935-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:13.780-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:57.563-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:41:00.556-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:42:22.562-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:24.331-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:42.247-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:32.498-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:55.917-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:19.198-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:43.240-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:20.406-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:40.634-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:37.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6550" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allow memory corruption</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3460"/>
        <description>Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:41.509-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:13.384-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:57.136-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:41:00.462-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:41:52.470-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:23.689-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:44.135-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:31.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:57.160-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:18.375-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:45.414-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:19.457-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:43.391-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:36.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6548" version="17" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0 via unspecified vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3373"/>
        <description>Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:24.327-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:19.841-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:15.366-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6548 - Corrected capitalization and extra spacing errors in product names" date="2011-04-08T16:13:00.153-04:00">
              <contributor organization="AIST">Akihito Nakamura</contributor>
            </modified>
            <status_change date="2011-04-08T16:17:43.496-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:24.179-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5310 - Update to oval:org.mitre.oval:ste:5310 to deal with versions 10 and above." date="2012-02-21T14:57:00.905-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2012-02-21T14:59:32.880-05:00">INTERIM</status_change>
            <status_change date="2012-03-12T04:00:45.289-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:33:51.993-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:46.914-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:59:37.077-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:11:59.822-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6548 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:36.622-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:48.474-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6548 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:37.985-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:16.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:10.374-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:13.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.15" test_ref="oval:org.mitre.oval:tst:121013"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey before 2.0 is installed" test_ref="oval:org.mitre.oval:tst:100052"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6543" version="5" class="vulnerability">
      <metadata>
        <title>Opera before 10.10 has unknown impact and attack vectors vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4072"/>
        <description>Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-26T01:37:29.630">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-11-30T14:35:04.396-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:08.949-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:56.100-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:15.510-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:26.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10913 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:10.118-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:48.606-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.10" test_ref="oval:org.mitre.oval:tst:10913"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6541" version="13" class="vulnerability">
      <metadata>
        <title>Spoofed file extensions via a crafted filename containing Unicode character in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3376"/>
        <description>Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:24.611-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:19.288-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:14.756-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:33:55.930-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:46.438-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5545 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:57:26.539-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:11:59.436-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6541 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:40.873-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:48.322-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6541 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:39.644-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:16.404-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:10.683-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:13.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.15" test_ref="oval:org.mitre.oval:tst:121013"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey version less than 2.0" test_ref="oval:org.mitre.oval:tst:100036"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6534" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allow to execute arbitrary code via a crafted PDF file</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3459"/>
        <description>Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:41.155-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:12.934-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:56.673-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:41:00.200-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:41:36.205-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:23.099-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:39.927-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:31.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:31.304-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:17.431-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:40.369-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:18.426-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:05.213-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:35.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6532" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat denial of service (application crash) via a PDF</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3431"/>
        <description>Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:40.411-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:12.545-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:56.268-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:40:00.178-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:41:19.185-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:22.358-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:44.707-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:30.720-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:37.142-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:16.692-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:46.117-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:17.669-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:12.295-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:34.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6530" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player before 11.5.2.602 allows to cause a denial of service and possibly execute arbitrary code</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3244"/>
        <description>Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T08:55:31.430-04:00">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:39.349-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:07.786-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:51.827-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:08.149-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:32.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="check for the version Adobe shockwave player" test_ref="oval:org.mitre.oval:tst:10555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6528" version="10" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Floating Point Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689"/>
        <description>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:21.128-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:18.895-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:14.419-05:00">ACCEPTED</status_change>
            <modified comment="Updated CVE reference" date="2010-01-25T10:54:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2010-01-25T10:54:00.000-05:00">INTERIM</status_change>
            <status_change date="2010-02-15T04:00:02.490-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:47.159-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:45.970-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6528 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:30.493-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:16.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:15.403-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:13.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Mozilla Firefox Mainline version is 3.0.x to 3.0.14" test_ref="oval:org.mitre.oval:tst:120713"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6526" version="8" class="vulnerability">
      <metadata>
        <title>Excel Index Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer 2003</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3132"/>
        <description>Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed formula, related to a "pointer corruption" issue, aka "Excel Index Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:37.700-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:55.773-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:06.587-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:00.566-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:25.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:45.733-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:32.069-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:09.853-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:19.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11111"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8316.0" test_ref="oval:org.mitre.oval:tst:11073"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:10885"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="Xlview.exe version is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:11121"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11080"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6524" version="1" class="vulnerability">
      <metadata>
        <title>Maxthon Browser Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Maxthon Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3018"/>
        <description>Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header; does not properly block data: URIs in Location headers in HTTP responses, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within (a) 301 and (b) 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (7) injecting a Location HTTP response header or (8) specifying the content of a Location HTTP response header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-23T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-23T14:56:41.355-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:14.134-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:52.829-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Maxthon Browser is installed" definition_ref="oval:org.mitre.oval:def:6262"/>
        <criterion comment="Maxthon Browser version is equal to 3.0.0.145" test_ref="oval:org.mitre.oval:tst:10779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6521" version="8" class="vulnerability">
      <metadata>
        <title>Excel Featheader Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer 2003</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3129" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3129"/>
        <description>Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:37.115-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:55.068-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:05.830-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:23:55.520-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:24.890-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:39.482-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:31.425-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:09.011-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:19.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11111"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8316.0" test_ref="oval:org.mitre.oval:tst:11073"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:10885"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="Xlview.exe version is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:11121"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11080"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6519" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-3673)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3673"/>
        <description>Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:11.285-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:36.101-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:09.430-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:36:00.088-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:37:29.096-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:18.819-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.931-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.931-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:15.109-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:10.718-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6578 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-17T04:00:29.521-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6519 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:56.517-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:15.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18349" test_ref="oval:org.mitre.oval:tst:10560"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22550" test_ref="oval:org.mitre.oval:tst:11161"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18130" test_ref="oval:org.mitre.oval:tst:11275"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22252" test_ref="oval:org.mitre.oval:tst:11036"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18854" test_ref="oval:org.mitre.oval:tst:10325"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22945" test_ref="oval:org.mitre.oval:tst:11217"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18865" test_ref="oval:org.mitre.oval:tst:11230"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22956" test_ref="oval:org.mitre.oval:tst:11290"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:21026"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16466" test_ref="oval:org.mitre.oval:tst:11033"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20579" test_ref="oval:org.mitre.oval:tst:10797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6518" version="8" class="vulnerability">
      <metadata>
        <title>Excel Formula Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer 2003</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3131"/>
        <description>Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet with a crafted formula embedded in a cell, aka "Excel Formula Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:36.174-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:54.592-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:05.130-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:06.890-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:24.082-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:51.077-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:30.678-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:11.024-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:19.158-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11111"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8316.0" test_ref="oval:org.mitre.oval:tst:11073"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:10885"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="Xlview.exe version is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:11121"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11080"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="Excelcnv.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6516" version="5" class="vulnerability">
      <metadata>
        <title>OPTIONS Request in WebKit in Apple Safari Cross-Site Request Forgery (CSRF) Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2816"/>
        <description>The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:28.792-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:01:00.725-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:35.598-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:41.273-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:30.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:17.335-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:11.437-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.21.10" test_ref="oval:org.mitre.oval:tst:10529"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6510" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework</product>
          <product>Microsoft Silverlight</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2497"/>
        <description>The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:56.292-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:11.485-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:53.775-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:44.002-05:00">INTERIM</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:00:00.766-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.229-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.547-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-21T04:01:02.891-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6510 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:03.553-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:11.266-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6510 - Modified criteria to match MS bulletin" date="2014-06-13T17:54:00.121-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:57:28.713-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:18.906-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6510 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:53.321-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:14.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 2.0 on Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1003" test_ref="oval:org.mitre.oval:tst:21588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 on Windows 2000, XP, Server 2003, Vista, Server 2008">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="GDR or LDR Service Branch">
            <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.3603" test_ref="oval:org.mitre.oval:tst:10670"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Mscorlib.dll is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:41709"/>
              <criterion comment="Mscorlib.dll is less than 2.0.50727.4062" test_ref="oval:org.mitre.oval:tst:21461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="GDR or LDR Service Branch">
            <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.3603" test_ref="oval:org.mitre.oval:tst:10670"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Mscorlib.dll is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:41709"/>
              <criterion comment="Mscorlib.dll is less than 2.0.50727.4062" test_ref="oval:org.mitre.oval:tst:21461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 on Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="GDR or LDR">
            <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.4200" test_ref="oval:org.mitre.oval:tst:10981"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.4400" test_ref="oval:org.mitre.oval:tst:10805"/>
              <criterion comment="the version of Mscorlib.dll is greater than or equal to 2.0.50727.4300" test_ref="oval:org.mitre.oval:tst:41546"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6509" version="3" class="vulnerability">
      <metadata>
        <title>Avast! Home and Professional 'ashWsFtr.dll' Unspecified Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3524"/>
        <description>Unspecified vulnerability in ashWsFtr.dll in Avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:37.199-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:13.761-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:50.838-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:15.971-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:30.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criterion comment="Avast! version is less than 4.8.1356.0" test_ref="oval:org.mitre.oval:tst:10746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6499" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allow arbitrary code execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3458" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3458"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:40.755-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:09.245-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:51.590-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:40:00.427-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:40:59.435-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:21.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:35.522-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:29.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:27.825-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:14.671-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:33.086-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:16.734-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:25.925-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:33.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6495" version="9" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 to cause a denial of service.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3381" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3381"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:21.825-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:18.010-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:12.665-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:45.909-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:45.633-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6495 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:36.819-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:16.114-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:15.334-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:12.895-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6487" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat Multiple Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:32.420-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:06.896-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:49.512-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:40:00.494-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:40:41.501-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:20.671-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:43.529-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:28.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:35.943-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:13.823-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:44.716-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:15.852-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:10.708-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:33.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6483" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2988"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:36.369-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:05.709-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:48.314-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:40:00.289-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:40:23.295-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:20.136-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:45.904-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:28.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:38.337-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:12.772-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:47.546-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:14.895-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:14.443-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:32.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6481" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause arbitrary code execution via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2997" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2997"/>
        <description>Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:39.624-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:05.284-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:47.789-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:39:00.192-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:40:03.199-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:19.537-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:36.615-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:27.474-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:22.808-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:11.961-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:34.459-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:14.119-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:54.801-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:31.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6475" version="5" class="vulnerability">
      <metadata>
        <title>WebKit in Apple Safari Numeric Character References Remote Memory Corruption Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3016"/>
        <description>Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:28.530-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:59.426-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:35.196-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:09.111-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:27.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:32.145-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:10.653-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is equal to 4.531.9.1" test_ref="oval:org.mitre.oval:tst:11000"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6474" version="6" class="vulnerability">
      <metadata>
        <title>Excel SxView Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Office Excel Viewer 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3128"/>
        <description>Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:36.817-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:46.964-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:00.746-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:55.414-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:20.698-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:55:58.852-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:18.148-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11111"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8316.0" test_ref="oval:org.mitre.oval:tst:11073"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="Xlview.exe version is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:11121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6470" version="12" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player Unspecified Remote Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Flash Player</product>
          <product>Adobe AIR</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0519"/>
        <description>Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T03:25:55">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:30.319-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:00.400-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:40.932-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7075 - Changed to match Flash Player ActiveX as well as the Plugin." date="2010-01-14T21:25:00.737-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-14T21:26:51.586-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:25.148-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11159 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:19.869-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:13.668-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:09:16.200-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:07.789-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-02T15:25:11.983-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.074-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6470 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-09-17T10:29:18.741-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:12.731-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6470 - Added criteria for Adobe air." date="2015-02-26T19:32:00.874-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-26T19:35:36.690-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:57.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Flash Player section">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criteria operator="OR" comment="Vulnerable version of Adobe Flash Player">
            <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:10855"/>
            <criteria operator="AND" comment="Vulnerable version of Adobe Flash Player 10">
              <criterion comment="Adobe Flash Player version installed on the system is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:11224"/>
              <criterion comment="Adobe Flash Player version installed on the system is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:11159"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Flash.ocx section">
          <criterion comment="Determine if the version of Flash.ocx is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:122849"/>
          <criteria operator="AND" comment="Vulnerable version of Flash.ocx">
            <criterion comment="Determine if the version of Flash.ocx is greater than or equal 10.0" test_ref="oval:org.mitre.oval:tst:122955"/>
            <criterion comment="Determine if the version of Flash.ocx is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:122989"/>
          </criteria>
        </criteria>
        <criteria comment="Adobe AIR section">
          <extend_definition comment="Adobe AIR is installed" definition_ref="oval:org.mitre.oval:def:7479"/>
          <criterion comment="Check if the version of Adobe AIR is less than or equal 1.5" test_ref="oval:org.mitre.oval:tst:138162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6466" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allows attackers to bypass intended file-extension</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3461"/>
        <description>Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:41.866-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:03.562-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:45.744-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:39:00.800-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:39:46.808-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:18.722-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:45.315-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:26.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:57.779-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:11.219-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:46.795-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:13.298-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:42.610-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:30.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6464" version="9" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3371"/>
        <description>Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:23.275-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:17.345-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:12.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:26.546-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:45.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6464 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:26.658-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:15.982-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:13.059-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:12.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6460" version="7" class="vulnerability">
      <metadata>
        <title>Opera before 10.00 allow remote attacks to spoof URLs</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3047"/>
        <description>Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers to spoof URLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T12:57:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:01.342-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:17.918-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:19.539-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:37.681-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:20.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:28339 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:18.358-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:23.007-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6460 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:38.062-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:28.723-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.0" test_ref="oval:org.mitre.oval:tst:10765"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6455" version="9" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3370"/>
        <description>Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:23.465-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:16.862-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:11.744-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:17.627-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:44.538-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6455 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:35.166-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:15.754-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:12.213-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:12.471-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Mozilla Firefox Mainline version is 3.0.x to 3.0.14" test_ref="oval:org.mitre.oval:tst:120713"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6451" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework Type Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0091"/>
        <description>Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:55.796-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:00.874-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:43.442-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:43.811-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:59.410-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6451 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:04.858-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:09.626-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6451 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:55.974-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:13.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 2.0 on Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1003" test_ref="oval:org.mitre.oval:tst:21588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1934" version="6" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 2.0 (Original RTM or later) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:2.0"/>
        <description>Microsoft .NET Framework 2.0 (Original RTM or later) is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:05.115-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:15.137-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.577-04:00">ACCEPTED</status_change>
            <status_change date="2007-09-13T11:07:56.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1934 - Updated to check registry keys instead of version of DLL." date="2011-01-13T14:14:00.592-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:16:15.689-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:14.357-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1934 - MS Oct 2013 bulletin ms13-081-n-082 (.Net 2 inventory CPE added)" date="2013-10-17T11:45:00.437-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-10-17T11:49:24.854-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:02.396-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Is the Microsoft .NET Framework 2.0 installed" test_ref="oval:org.mitre.oval:tst:42091"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6444" version="7" class="vulnerability">
      <metadata>
        <title>Opera before 10.00 does not properly handle a \0 character or invalid wildcard character</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3044"/>
        <description>Opera before 10.00 does not properly handle a (1) '\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T12:57:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:00.714-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:17.666-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:19.264-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:52.678-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:19.787-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:28339 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:17.694-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.944-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6444 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:39.497-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:28.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.0" test_ref="oval:org.mitre.oval:tst:10765"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6443" version="9" class="vulnerability">
      <metadata>
        <title>The oggplay_data_handle_theora_frame in liboggplay in Mozilla Firefox 3.5.x before 3.5.4 to cuase denial of service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3378"/>
        <description>The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:22.452-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:16.495-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:11.371-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:53.811-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:43.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6443 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:31.910-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:15.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:19.333-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:12.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6442" version="7" class="vulnerability">
      <metadata>
        <title>Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3045"/>
        <description>Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted server certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T12:57:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:00.911-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:17.425-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:18.938-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:52.401-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:19.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:28339 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:17.604-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.877-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6442 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:33.505-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:28.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.0" test_ref="oval:org.mitre.oval:tst:10765"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6437" version="1" class="vulnerability">
      <metadata>
        <title>Maxthon Browser Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Maxthon Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3006"/>
        <description>Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-23T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-23T14:56:41.097-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:10.939-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:46.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Maxthon Browser is installed" definition_ref="oval:org.mitre.oval:def:6262"/>
        <criterion comment="Maxthon Browser version is equal to 2.5.8.0" test_ref="oval:org.mitre.oval:tst:10908"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6262" version="1" class="inventory">
      <metadata>
        <title>Maxthon Browser is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Maxthon Browser</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:maxthon:maxthon_browser:"/>
        <description>The operating system having Maxthon Browser installation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-23T10:27:37">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-23T14:56:40.656-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:08.792-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:44.795-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
        </criteria>
        <criterion comment="Maxthon Browser is installed" test_ref="oval:org.mitre.oval:tst:11008"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6435" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin before 2.6.2 allow denial of service via TOPIC message</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703"/>
        <description>libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T01:41:17">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:26.265-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:17.129-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:18.594-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6435 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:16.184-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:44.423-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Pidgin is installed" definition_ref="oval:org.mitre.oval:def:12366"/>
        <criterion comment="Pidgin version is less than 2.6.2" test_ref="oval:org.mitre.oval:tst:10810"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6434" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin before 2.6.2 allow denial of service via XHTML-IM content</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3085"/>
        <description>The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T01:41:17">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:27.140-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:16.754-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:18.265-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6434 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:18.363-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:43.967-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Pidgin is installed" definition_ref="oval:org.mitre.oval:def:12366"/>
        <criterion comment="Pidgin version is less than 2.6.2" test_ref="oval:org.mitre.oval:tst:10810"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6429" version="17" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Adobe Reader and Acrobat 'format bug' remote arbitrary code execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3462"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:42.253-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:58.564-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:42.682-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:39:00.483-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:39:27.490-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:17.989-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:49.497-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:25.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:44.792-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:10.423-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:51.784-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:10.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:55.457-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:29.833-04:00">ACCEPTED</status_change>
            <modified comment="not applicable to Windows" date="2014-05-29T11:38:13.071-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-29T11:38:13.071-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6421" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>ATL COM Initialization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493"/>
        <description>The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:02.292-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:56.358-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:41.161-05:00">ACCEPTED</status_change>
            <modified comment="Deprecated after consolidating other definitions for the same CVE. The new consolidated definition is oval:org.mitre.oval:def:6716" date="2010-01-03T18:00:11.513-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-03T18:00:11.513-04:00">DEPRECATED</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.946-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10568"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10739"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10428"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10956"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10741"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10559"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10837"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10923"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10592"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10657"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10978"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10876"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10927"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10844"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:11009"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10968"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10708"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10997"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10786"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10822"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10892"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10680"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10951"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10887"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10198"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10986"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10698"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10823"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10819"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10829"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6418" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allow arbitrary code execution and DoS</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2998" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2998"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:40.068-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:54.665-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:39.207-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:35:00.511-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:39:08.517-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:17.478-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6418 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:14.597-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:25.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:34.854-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:09.349-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:37.996-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:09.755-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:35.306-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:28.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6416" version="5" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause DOS.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2560"/>
        <description>Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:19.714-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:16.431-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:17.848-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:27.962-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:19.548-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6416 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:43.136-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:09.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criteria operator="OR" comment="Wireshark version 1.0.8 or 1.2.0">
          <criterion comment="Check the version of Wireshark installed is equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:10682"/>
          <criterion comment="Check the version of Wireshark installed is equal to 1.0.8" test_ref="oval:org.mitre.oval:tst:10789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6413" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the TLS dissector in Wireshark which causes DOS.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3243"/>
        <description>Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:18.992-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:16.102-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:17.457-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:28.322-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:19.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6413 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:27.528-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:09.003-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed less than or equal to 1.2.1" test_ref="oval:org.mitre.oval:tst:10713"/>
        <criterion comment="Check the version of Wireshark installed greater than or equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:10735"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6405" version="10" class="vulnerability">
      <metadata>
        <title>Apple QuickTime before 7.6.4 allows Heap-based buffer overflow and DOS Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2799"/>
        <description>Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T10:30:41">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:35.130-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:15.812-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:17.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:10.537-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:24.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:38.589-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:13.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6405 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:32.281-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:39.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6405 - The extended definition Apple QuickTime is installed was added to avoid error." date="2014-01-14T17:01:00.214-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:02:56.447-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6405 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-02-03T04:04:48.182-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.4 (7.64.17.73)" test_ref="oval:org.mitre.oval:tst:10538"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6398" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.5.x before 3.5.3 JavaScript engine allow denial of service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3073"/>
        <description>Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:29.768-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:15.529-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:16.769-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:47.885-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:43.385-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6398 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:34.886-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:27.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.2" test_ref="oval:org.mitre.oval:tst:10798"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6395" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player before 11.5.2.602 allows Remote Code Execution invalid string length Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3466"/>
        <description>Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T08:55:31.430-04:00">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:39.166-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:56.393-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:39.364-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:05.710-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:31.831-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="check for the version Adobe shockwave player" test_ref="oval:org.mitre.oval:tst:10555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6394" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player before 11.5.2.602 allows Remote Code Execution invalid pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3464"/>
        <description>Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T08:55:31.430-04:00">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:38.676-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:56.020-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:38.809-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:05.783-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:31.516-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="check for the version Adobe shockwave player" test_ref="oval:org.mitre.oval:tst:10555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6391" version="9" class="vulnerability">
      <metadata>
        <title>Wireshark Denial of Service vulnerability caused by packet-paltalk.c in the Paltalk dissector</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3549"/>
        <description>packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:17.816-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:56.385-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:33.132-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6391 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:24.248-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:18.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5067 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:45.930-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:59.593-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:19.182-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:18.703-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6391 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:48.130-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:08.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed on the system is 1.2.0 through 1.2.2" test_ref="oval:org.mitre.oval:tst:10498"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6385" version="5" class="vulnerability">
      <metadata>
        <title>Opera before 10.10 allows to obtain sensitive information and XSS attacks</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4071"/>
        <description>Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a different web site, which allows remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-26T01:37:29.630">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-11-30T14:35:04.182-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:55.512-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:37.843-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:48.768-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:18.773-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10913 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:10.069-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:47.949-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.10" test_ref="oval:org.mitre.oval:tst:10913"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6384" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption error in Opera before 10.01 when processing malformed domain names</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3832" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3832"/>
        <description>Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-24T10:31:45.529">
              <contributor organization="SecPod Technologies">Nikita MR</contributor>
            </submitted>
            <status_change date="2009-11-24T14:51:39.685-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:10.548-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:45.979-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:49.451-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:18.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:28339 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:17.374-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:47.813-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.01" test_ref="oval:org.mitre.oval:tst:11074"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6382" version="8" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-3671)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3671"/>
        <description>Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3674.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:08.129-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:32.144-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:07.665-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:35:00.638-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:36:50.645-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:15.412-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.244-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.244-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:12.339-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6578 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:19.296-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:27.611-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6382 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:49.502-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:12.679-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18854" test_ref="oval:org.mitre.oval:tst:10325"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22945" test_ref="oval:org.mitre.oval:tst:11217"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18865" test_ref="oval:org.mitre.oval:tst:11230"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22956" test_ref="oval:org.mitre.oval:tst:11290"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:21026"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16466" test_ref="oval:org.mitre.oval:tst:11033"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20579" test_ref="oval:org.mitre.oval:tst:10797"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6379" version="5" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the IPMI dissector in Wireshark.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2559" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2559"/>
        <description>Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:19.372-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:15.219-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:16.414-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:13.627-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:18.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6379 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:55.566-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:08.138-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check the version of Wireshark installed is equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:10682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6375" version="9" class="vulnerability">
      <metadata>
        <title>vulnerabilities in liboggz, as used in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3377"/>
        <description>Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:22.649-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:15.934-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:10.163-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:31.682-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:42.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6375 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:30.344-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:15.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:13.362-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:12.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6371" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allow attackers to execute arbitrary code via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2990"/>
        <description>Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:37.068-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:50.978-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:35.657-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:34:00.257-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:35:14.265-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:16.614-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:48.301-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:23.832-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:03.491-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:08.628-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:50.408-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:07.255-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:51.061-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:28.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6370" version="7" class="vulnerability">
      <metadata>
        <title>Cross-site scripting (XSS) vulnerability in Opera 9 and 10</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3265"/>
        <description>Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the vendor reportedly considers this behavior a "design feature," not a vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T04:01:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:44.181-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:14.896-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:16.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:42.841-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:17.920-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5298 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:10.947-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.664-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10629 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:34.528-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:27.306-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version 9.x to 10.0.x" test_ref="oval:org.mitre.oval:tst:10629"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6365" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat social engineering attack via unknown vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2982"/>
        <description>An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers to conduct a "social engineering attack" via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:34.272-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:50.138-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:34.705-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:34:00.182-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:34:54.189-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:16.084-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:40.492-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:23.220-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:54.746-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:07.769-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:41.087-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:05.750-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:38.004-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:27.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6362" version="5" class="vulnerability">
      <metadata>
        <title>WebKit in Apple Safari Multiple Unspecified Vulnerabilities.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3384"/>
        <description>Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:29.236-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:56.020-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:30.857-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:24.613-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:22.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:54.141-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:10.163-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.21.10" test_ref="oval:org.mitre.oval:tst:10529"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6358" version="7" class="vulnerability">
      <metadata>
        <title>Opera 'keygen' HTML Tag Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3269"/>
        <description>Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic submissions of a form containing a KEYGEN element, a related issue to CVE-2009-1828.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T03:15:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:54.425-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:14.661-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:15.781-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:30.900-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:17.458-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10808 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:13.186-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.602-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6358 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:33.352-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:27.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera version is less than 9.53" test_ref="oval:org.mitre.oval:tst:10808"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6357" version="7" class="vulnerability">
      <metadata>
        <title>Opera before 10.00 does not check all intermediate X.509 certificates for revocation</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3046"/>
        <description>Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T12:57:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:01.149-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:14.383-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:15.493-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:29.288-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:16.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6357 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:13.318-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.533-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6357 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:35.887-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:27.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.0" test_ref="oval:org.mitre.oval:tst:10765"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6350" version="7" class="vulnerability">
      <metadata>
        <title>Opera 9.52 and earlier allows to cause denial of service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-7245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7245"/>
        <description>Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T03:15:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:54.624-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:14.113-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:15.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:29.566-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:15.979-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10808 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:13.136-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.474-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6350 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:38.959-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:26.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera version is less than 9.53" test_ref="oval:org.mitre.oval:tst:10808"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6348" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat DoS via long sequence of # (hash) characters</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0048"/>
        <description>Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:32.063-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:49.351-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:33.948-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:34:00.955-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:34:33.963-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:14.966-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:42.915-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:22.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:35.352-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:06.959-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:43.912-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:04.649-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:11.488-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:26.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6347" version="17" class="vulnerability">
      <metadata>
        <title>Arbitrary code execution in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0 ia a crafted regular expression in a Proxy Auto-configuration (PAC) file.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
          <product>Mozilla Seamonkey</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3372"/>
        <description>Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:24.099-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:14.890-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:09.254-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6347 - Corrected capitalization and extra spacing errors in product names" date="2011-04-08T16:13:00.153-04:00">
              <contributor organization="AIST">Akihito Nakamura</contributor>
            </modified>
            <status_change date="2011-04-08T16:17:41.478-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:23.759-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5310 - Update to oval:org.mitre.oval:ste:5310 to deal with versions 10 and above." date="2012-02-21T14:57:00.905-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2012-02-21T14:59:34.333-05:00">INTERIM</status_change>
            <status_change date="2012-03-12T04:00:44.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:04.354-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:41.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6012 - definitions for the latest CVEs for Firefox, Thunderbird, and SeaMonkey, along with a few updates." date="2013-09-19T17:54:00.261-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-09-19T17:59:48.525-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:11:56.170-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6347 - correct check of SeaMonkey existance and its version" date="2014-01-16T10:44:00.577-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:54:42.785-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:47.929-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6347 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:39.153-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:15.283-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:11.204-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:11.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Firefox mainline">
          <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Mozilla Firefox Mainline version is less than 3.0.15" test_ref="oval:org.mitre.oval:tst:121013"/>
            <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SeaMonkey">
          <extend_definition comment="Mozilla Seamonkey is installed" definition_ref="oval:org.mitre.oval:def:6372"/>
          <criterion comment="Mozilla Seamonkey before 2.0 is installed" test_ref="oval:org.mitre.oval:tst:100052"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6338" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin before 2.6.2 allow denial of service via handwritten (aka Ink) message</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3084"/>
        <description>The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T01:41:17">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:26.822-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:13.735-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:14.758-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6338 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:15.433-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:43.618-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Pidgin version is less than 2.6.2" test_ref="oval:org.mitre.oval:tst:10810"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6322" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin before 2.6.2 allow denial of service via SLP invite message</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083"/>
        <description>The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T01:41:17">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:26.557-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:13.411-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:14.397-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6322 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:20.656-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:43.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Pidgin is installed" definition_ref="oval:org.mitre.oval:def:12366"/>
        <criterion comment="Pidgin version is less than 2.6.2" test_ref="oval:org.mitre.oval:tst:10810"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6321" version="5" class="vulnerability">
      <metadata>
        <title>DOS vulnerability in the Infiniband dissector in Wireshark.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2563" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563"/>
        <description>Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:20.765-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:12.973-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:13.944-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:35.266-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:17.884-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6321 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:09.669-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:07.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed is less than or equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:9842"/>
        <criterion comment="Check for version of Wireshark installed is greater than or equal to 1.0.6" test_ref="oval:org.mitre.oval:tst:10747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6320" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin before 2.5.9 allow denial of service via SLP (aka MSNSLP) messages</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694"/>
        <description>The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location.  NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T03:13:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:43.565-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:12.648-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:13.570-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10316 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:16.939-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:42.755-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Pidgin is installed" definition_ref="oval:org.mitre.oval:def:12366"/>
        <criterion comment="Pidgin version is less than 2.5.9" test_ref="oval:org.mitre.oval:tst:10316"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6315" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3 allow denial of service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3072"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:29.542-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:12.344-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:13.230-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:04.705-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:41.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6315 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:37.422-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:26.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.2 or less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6314" version="7" class="vulnerability">
      <metadata>
        <title>Opera 9 and 10 allows remote attackers to conduct XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3266"/>
        <description>Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T04:01:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:43.948-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:11.824-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:12.872-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:49:03.435-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:13.024-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5298 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:10.890-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.415-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10629 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:34.456-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:26.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version 9.x to 10.0.x" test_ref="oval:org.mitre.oval:tst:10629"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6298" version="7" class="vulnerability">
      <metadata>
        <title>Project Memory Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Project 2000</product>
          <product>Microsoft Project 2002</product>
          <product>Microsoft Project 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0102"/>
        <description>Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-09T17:00:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2009-12-11T11:33:49.437-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:26.355-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:05.966-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6298 - Corrected typo in product name" date="2011-04-27T10:11:00.038-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2011-04-27T10:11:36.522-04:00">INTERIM</status_change>
            <status_change date="2011-05-16T04:03:18.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10877 - Made updates to MS09-074 - &quot;Microsoft Project 2003 SP 3 is included &amp; removed Project 2003 SP2&quot; in criteria &amp; authoring guide updates." date="2011-08-31T17:32:00.428-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-08-31T17:33:20.519-04:00">INTERIM</status_change>
            <status_change date="2011-09-15T10:59:33.153-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:120 - Updating pre-Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:55:00.075-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:57:19.988-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:05.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Project 2000 SR1 and Winproj.exe">
          <extend_definition comment="Microsoft Project 2000 SR1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <criterion comment="Winproj.exe version is less than 9.0.2009.1022" test_ref="oval:org.mitre.oval:tst:10815"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Project 2002 SP1 and Winproj.exe">
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="Winproj.exe version is less than 10.0.2108.2216" test_ref="oval:org.mitre.oval:tst:11223"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Project 2003 SP3 and Winproj.exe">
          <extend_definition comment="Microsoft Project 2003 SP3 is installed" definition_ref="oval:org.mitre.oval:def:5755"/>
          <criterion comment="Winproj.exe version is less than 11.3.2009.1108" test_ref="oval:org.mitre.oval:tst:10877"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5755" version="7" class="inventory">
      <metadata>
        <title>Microsoft Project 2003 SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Project 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:project:2003:sp3"/>
        <description>The application Microsoft Project 2003 SP3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:33.579-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:23.379-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:09.919-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5755 - Corrected typo in description" date="2011-04-27T13:32:00.314-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-27T13:32:54.897-04:00">INTERIM</status_change>
            <status_change date="2011-05-16T04:03:13.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:417 - Updating pre-Microsoft Office 2010 content to use windows_view behaviors." date="2012-05-10T14:55:00.075-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:57:34.278-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:01:57.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5755 - modified inventories for Microsoft Expression Design." date="2013-07-05T09:53:00.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:58:07.253-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:08.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Winproj.exe version is greater than or equal to 11.3.2007.1529" test_ref="oval:org.mitre.oval:tst:9528"/>
        <criterion comment="Registry key specifying where Microsoft Project 2003 exists" test_ref="oval:org.mitre.oval:tst:81453"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:518" version="4" class="inventory">
      <metadata>
        <title>Microsoft Project 2000 SR1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:project:2000:sr1"/>
        <description>The application Microsoft Project 2000 SR1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:48.768-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.303-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:5" date="2007-03-06T08:05:00.193-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-06T08:06:14.285-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:20.002-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5 - Made updates to MS09-074 - &quot;Microsoft Project 2003 SP 3 is included &amp; removed Project 2003 SP2&quot; in criteria &amp; authoring guide updates." date="2011-08-31T17:32:00.428-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-08-31T17:33:16.656-04:00">INTERIM</status_change>
            <status_change date="2011-09-15T10:59:32.286-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MS Project 2000 is installed." test_ref="oval:org.mitre.oval:tst:77"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6297" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause execution of arbitrary code vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2989"/>
        <description>Integer overflow in Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:36.692-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:46.789-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:32.302-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:33:00.225-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:34:15.233-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:14.408-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:46.522-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:21.544-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:41.048-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:05.992-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:48.253-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:03.406-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:17.449-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:25.283-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6290" version="11" class="vulnerability">
      <metadata>
        <title>Apple iTunes '.pls' File Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2817"/>
        <description>Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-01T10:31:31">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-10-09T14:07:18.903-04:00">DRAFT</status_change>
            <modified comment="Updated obj:6563 to use registry key that contains the full filepath of iTunes.exe" date="2009-10-19T16:03:00.949-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:46.516-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:31.972-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:51.849-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:24.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:44.142-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:07.815-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6290 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:50.617-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:38.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:52:45.011-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:06.690-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:48.154-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:46.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 9.0.1.8" test_ref="oval:org.mitre.oval:tst:10719"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6284" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat bypass intended Trust Manager restrictions via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2981"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to bypass intended Trust Manager restrictions via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:33.838-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:46.098-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:31.571-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:33:00.128-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:33:56.137-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:13.599-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:47.129-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:20.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:42.283-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:05.242-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:48.880-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:02.172-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:18.887-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:24.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6280" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat denial of service via a crafted document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2979"/>
        <description>Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:33.161-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:44.475-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:29.717-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:33:00.219-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:33:38.226-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:12.985-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:36.086-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:20.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:19.952-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:04.164-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:33.745-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:03:00.529-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:53.344-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:23.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6274" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause denial of service via unknown vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2987"/>
        <description>Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:35.999-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:43.665-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:28.502-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:32:00.514-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:33:17.521-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:12.411-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:37.715-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:19.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:24.477-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:02.793-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:35.835-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:59.495-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:52:56.990-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:22.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6263" version="5" class="vulnerability">
      <metadata>
        <title>Local Security Authority Subsystem Service Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2524"/>
        <description>Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:49.596-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:42.254-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:26.750-05:00">ACCEPTED</status_change>
            <modified comment="Added test to check for KB968389 on XP,2003 - Msv1_0.dll greater than or equal to check" date="2009-12-02T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Added tests to check for the installation of KB968389, which is a prerequisite to MS09-059 on Windows XP and 2003 per the security bulletin." date="2009-12-03T17:11:00.230-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-03T17:17:46.238-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:52.245-05:00">ACCEPTED</status_change>
            <modified comment="Added new tests to replace tests- 10787 and 10804, uses correct object 7340" date="2010-03-09T12:29:00.062-05:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-03-09T12:30:25.086-05:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:13.257-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.728-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.728-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:10.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Msv1_0.dll is less than 5.1.2600.3625" test_ref="oval:org.mitre.oval:tst:10744"/>
          <criterion comment="the version of Msv1_0.dll is greater than or equal to 5.1.2600.3592" test_ref="oval:org.mitre.oval:tst:11167"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Msv1_0.dll is less than 5.1.2600.5876" test_ref="oval:org.mitre.oval:tst:10761"/>
          <criterion comment="the version of Msv1_0.dll is greater than or equal to 5.1.2600.5834" test_ref="oval:org.mitre.oval:tst:11012"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x64 SP2, Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is less than 5.2.3790.4587" test_ref="oval:org.mitre.oval:tst:10736"/>
          <criterion comment="the version of Msv1_0.dll is greater than or equal to 5.2.3790.4530" test_ref="oval:org.mitre.oval:tst:11220"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10848"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6000.16926" test_ref="oval:org.mitre.oval:tst:10874"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10107"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6000.21125" test_ref="oval:org.mitre.oval:tst:10875"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10976"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6001.18330" test_ref="oval:org.mitre.oval:tst:10614"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10982"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6001.22518" test_ref="oval:org.mitre.oval:tst:10687"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10008"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6002.18111" test_ref="oval:org.mitre.oval:tst:10590"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Msv1_0.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10174"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.0.6002.22223" test_ref="oval:org.mitre.oval:tst:10399"/>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Msv1_0.dll version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20995"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.1.7600.16420" test_ref="oval:org.mitre.oval:tst:10985"/>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Msv1_0.dll version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20123"/>
          <criterion comment="the version of Msv1_0.dll is less than 6.1.7600.20524" test_ref="oval:org.mitre.oval:tst:10511"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6258" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime before 7.6.4 allows Heap-based buffer overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2798"/>
        <description>Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T10:30:41">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:34.877-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:11.225-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:12.211-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:06.387-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:19.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:44.283-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:12.869-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6258 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:24.969-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:38.448-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6258 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:39.440-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:47.671-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.4 (7.64.17.73)" test_ref="oval:org.mitre.oval:tst:10538"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6250" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3 allow remote arbitrary code Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3079"/>
        <description>Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:31.412-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:10.873-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:11.615-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:38.727-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:40.898-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6250 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:37.752-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:25.943-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.2 or less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6242" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox XSS nadn HTML injection Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1310"/>
        <description>Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T09:45:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:24.656-04:00">DRAFT</status_change>
            <modified comment="Modified platform to Microsoft Windows Server 2003" date="2009-05-25T10:32:00.713-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-15T04:01:12.047-04:00">INTERIM</status_change>
            <status_change date="2009-07-06T04:00:47.668-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:44.420-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:40.301-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6242 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:39.844-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:25.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Firefox version is less than or equal to 3.0.8" test_ref="oval:org.mitre.oval:tst:9841"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6235" version="9" class="vulnerability">
      <metadata>
        <title>Opera before 10.00 does not properly display all characters in Internationalized Domain Names</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3049"/>
        <description>Opera before 10.00 does not properly display all characters in Internationalized Domain Names (IDN) in the address bar, which allows remote attackers to spoof URLs and conduct phishing attacks, related to Unicode and Punycode.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T12:57:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:01.742-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:10.605-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:11.337-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:45.102-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:10.122-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6235 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:13.432-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.358-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6235 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:36.401-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:25.653-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6235 - modified Vulnerability definition of CVE-2009-3049 for Windows" date="2014-06-02T14:45:00.119-04:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-06-02T14:46:48.526-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:07:47.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than 10.0" test_ref="oval:org.mitre.oval:tst:10765"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6226" version="3" class="vulnerability">
      <metadata>
        <title>Avast! Home and Professional 'aswMon2.sys' Stack-based Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3522"/>
        <description>Stack-based buffer overflow in aswMon2.sys in Avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:36.813-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:08.462-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:44.267-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:16.300-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:18.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criterion comment="Avast! version is less than 4.8.1356.0" test_ref="oval:org.mitre.oval:tst:10746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6223" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-6472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6472"/>
        <description>The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T10:31:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-08T14:19:58.985-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:18.123-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:28.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:37.845-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:16.874-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6223 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:21.901-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:06.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Version of Wireshark is 0.99.7 through 1.0.4" test_ref="oval:org.mitre.oval:tst:81815"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6220" version="7" class="vulnerability">
      <metadata>
        <title>Opera cross-domain scripting attacks Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0915" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0915"/>
        <description>Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T10:31:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-08T14:19:59.544-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:17.381-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:28.213-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:03.455-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:09.544-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9724 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:09.219-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.299-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6220 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:40.600-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:25.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera version is less than 9.64 (9.64.10487.0)" test_ref="oval:org.mitre.oval:tst:9724"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6218" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime AVI Heap Based buffer overflow vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0003"/>
        <description>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:28.035-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:29.279-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:15.442-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:05.781-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:18.589-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:42.889-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:12.489-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6218 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:27.390-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:37.976-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6218 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:38.823-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:47.535-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6211" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime MP3 Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0004" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0004"/>
        <description>Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:28.308-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:28.913-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:14.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:07.655-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:17.883-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:44.967-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:12.111-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6211 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:36.798-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:37.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6211 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:37.655-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:47.370-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6208" version="9" class="vulnerability">
      <metadata>
        <title>Apple Safari Cross-site scripting (XSS) vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1724"/>
        <description>Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T09:00:11">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:37:09.861-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:10.331-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:10.978-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:15.952-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:17.580-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6208 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:26.770-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:37.145-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:41.655-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:08.482-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6208 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:38.098-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:47.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Safari.exe version is less than 4.530.19.1 (4.0.2)" test_ref="oval:org.mitre.oval:tst:10617"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6187" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime H.263 Unspecified Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0005"/>
        <description>Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:28.524-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:28.537-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:14.095-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:05.282-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:17.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:42.318-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:11.696-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6187 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:32.978-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:36.647-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6187 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:38.377-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:47.104-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6186" version="8" class="vulnerability">
      <metadata>
        <title>Integer Overflow in X.509 Object Identifiers Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2511"/>
        <description>Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:07.588-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:39.286-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:24.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6186 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:16:00.750-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:19:21.125-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:21.159-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.978-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.978-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:09.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6186 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:15.270-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:09.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msasn1.dll is less than 5.0.2195.7334" test_ref="oval:org.mitre.oval:tst:10655"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.3624" test_ref="oval:org.mitre.oval:tst:10905"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.5875" test_ref="oval:org.mitre.oval:tst:10731"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of msasn1.dll is less than 5.2.3790.4584" test_ref="oval:org.mitre.oval:tst:10013"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6000.16922" test_ref="oval:org.mitre.oval:tst:10512"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44028"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6000.21122" test_ref="oval:org.mitre.oval:tst:43659"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6001.18326" test_ref="oval:org.mitre.oval:tst:10835"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44222"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6001.22515" test_ref="oval:org.mitre.oval:tst:43926"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6002.18106" test_ref="oval:org.mitre.oval:tst:10818"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:44044"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6002.22218" test_ref="oval:org.mitre.oval:tst:44105"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.1.7600.16415" test_ref="oval:org.mitre.oval:tst:10587"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:10901"/>
              <criterion comment="the version of msasn1.dll is less than 6.1.7600.20518" test_ref="oval:org.mitre.oval:tst:10706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6167" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin 2.6.0 and prior allow to cause a denial of service via Yahoo IM.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3025"/>
        <description>Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T03:13:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:43.896-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:09.948-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:10.624-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10807 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:19.891-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:42.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Pidgin is installed" definition_ref="oval:org.mitre.oval:def:12366"/>
        <criterion comment="Pidgin version is less than or equal to 2.6.0" test_ref="oval:org.mitre.oval:tst:10807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6162" version="5" class="vulnerability">
      <metadata>
        <title>DOS vulnerability in the OpcUa (OPC UA) dissector in Wireshark.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3241"/>
        <description>Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:18.376-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:09.605-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:10.246-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:22.677-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:16.520-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6162 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:15.313-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:05.857-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed less than or equal to 1.2.1" test_ref="oval:org.mitre.oval:tst:10713"/>
        <criterion comment="Check the version of Wireshark installed greater than or equal to 0.99.6" test_ref="oval:org.mitre.oval:tst:10740"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6160" version="8" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Adobe Flash Player unspecified information disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0521"/>
        <description>Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-30T03:25:55">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-12-01T18:37:32.611-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:48.352-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:33.776-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7075 - Changed to match Flash Player ActiveX as well as the Plugin." date="2010-01-14T21:25:00.737-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-14T21:26:51.497-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:21.626-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:11159 - Replaced references to duplicate Objects. Fixed references to Adobe Flash Player that incorrectly checked Adobe Acrobat 9." date="2012-12-12T17:23:00.847-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T17:28:18.344-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:11.244-05:00">ACCEPTED</status_change>
            <modified comment="Definition describes a Windows platform check for a Unix Vulnerability." date="2013-01-02T18:13:50.078-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-01-02T18:13:50.078-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Check 32 and 64 bit registries." date="2013-06-11T12:05:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7290 - Modificated object oval:org.mitre.oval:obj:7290" date="2013-12-02T15:23:00.894-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:tst:11224 - checks the version of Flash .ocx" date="2014-09-17T10:26:00.393-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
        <criteria operator="OR">
          <criterion comment="Adobe Flash Player version installed on the system is less than 9.0.159.0" test_ref="oval:org.mitre.oval:tst:10855"/>
          <criteria operator="AND">
            <criterion comment="Adobe Flash Player version installed on the system is greater than or equal to 10.0" test_ref="oval:org.mitre.oval:tst:11224"/>
            <criterion comment="Adobe Flash Player version installed on the system is less than 10.0.22.87" test_ref="oval:org.mitre.oval:tst:11159"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6156" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allow attackers to execute arbitrary code via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2994"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:38.455-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:37.746-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:22.689-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:32:00.182-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:32:39.188-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:11.657-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:38.268-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:16.639-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:50.762-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:01.874-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:36.579-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:55.778-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:32.442-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:21.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6153" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime cinepak Heap Based buffer overflow vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0006"/>
        <description>Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:28.818-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:28.175-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:13.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:07.927-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:16.332-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:45.328-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:10.844-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6153 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:59.924-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:36.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6153 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:38.987-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:46.986-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6146" version="6" class="vulnerability">
      <metadata>
        <title>Excel Cache Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Office Excel Viewer 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3127"/>
        <description>Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:36.549-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:22.339-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:47.496-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1360 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:59.712-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:02:08.505-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:01.671-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:16.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11111"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8316.0" test_ref="oval:org.mitre.oval:tst:11073"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="Xlview.exe version is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:11121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6145" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause DoS and Arbitrary Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2985"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:35.333-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:37.319-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:21.868-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:31:00.812-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:32:18.819-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:11.072-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6145 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:16.983-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:15.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:44.991-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:03:00.631-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:52.526-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:53.633-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:23.655-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:21.191-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6142" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the TEA decoding algorithm in Rhino Software Serv-U</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Rhino Software Serv-U</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4006"/>
        <description>Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:56.169-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:07.978-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:43.303-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:175 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:38.382-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:15.360-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6142 - Typo Corrections" date="2014-05-22T11:03:00.270-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:06:06.424-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:46.056-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Rhino Software Serv-U is installed" definition_ref="oval:org.mitre.oval:def:5875"/>
        <criterion comment="Test for Rhino Software Serv-U version less than 9.1.0.0" test_ref="oval:org.mitre.oval:tst:11096"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6140" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14 allow remote arbitrary code execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076"/>
        <description>Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:30.643-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:09.275-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:09.842-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:33:54.612-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:39.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6140 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:34.033-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:24.627-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10599"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6135" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime RTSP URL Heap Based buffer overflow vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0001"/>
        <description>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:29.050-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:27.769-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:12.729-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:08.262-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:14.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:33.677-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:10.480-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6135 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:38.113-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:35.638-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6135 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:39.892-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:46.870-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6132" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime JPEG Heap Based buffer overflow vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0007"/>
        <description>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:29.267-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:27.357-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:11.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:07.150-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:14.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:32.877-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:10.075-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6132 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:28.674-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:35.218-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6132 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:37.796-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:46.757-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6099" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark LDAP dissector Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1267"/>
        <description>Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-16T16:30:43">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-21T14:30:40.197-04:00">DRAFT</status_change>
            <status_change date="2009-05-11T04:00:36.329-04:00">INTERIM</status_change>
            <status_change date="2009-06-01T04:00:21.390-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:17.951-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:15.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6099 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:37.857-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:05.321-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Version of Wireshark is 0.99.2 through 1.0.6" test_ref="oval:org.mitre.oval:tst:81797"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6091" version="11" class="vulnerability">
      <metadata>
        <title>Apple Safari Malformed URI Remote Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0321"/>
        <description>Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-03T09:00:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:52.398-05:00">DRAFT</status_change>
            <modified comment="Changed the product from Apple Quicktime to Apple Safari" date="2009-02-13T15:23:00.550-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2009-03-02T04:00:24.013-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:18.959-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:39.534-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:14.082-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6091 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:20.308-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:34.731-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:15.091-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:07.756-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6091 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:39.295-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:46.630-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6091 - Typo Corrections" date="2014-05-22T11:01:00.943-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:03:40.121-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:45.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Safari.exe version is less than or equal to 3.525.27.1" test_ref="oval:org.mitre.oval:tst:9703"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6075" version="7" class="vulnerability">
      <metadata>
        <title>HIS Command Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Host Integration Server 2000</product>
          <product>Microsoft Host Integration Server 2004 Client</product>
          <product>Microsoft Host Integration Server 2004</product>
          <product>Microsoft Host Integration Server 2006</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3466"/>
        <description>Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:44.635-04:00">DRAFT</status_change>
            <modified comment="Added tests for HIS 2000 SP2 and HIS Administration Client" date="2008-10-27T09:22:00.865-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.315-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:40.715-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:08.211-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6408 - def:6075, Edited var:620 &amp; obj:6408 to use regex &amp; match different MS HIS version directories" date="2011-11-15T14:52:00.918-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:53:33.555-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:36.651-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:49:06.547-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:02:02.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:29.051-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:14.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Host Integration Server 2006">
          <extend_definition comment="Microsoft Host Integration Server 2006 is installed" definition_ref="oval:org.mitre.oval:def:5373"/>
          <criterion comment="Snarpcsv.exe version is less than 7.0.2900.0" test_ref="oval:org.mitre.oval:tst:9228"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Host Integration Server 2004/Client">
          <criteria operator="OR" comment="Check for Host Integration Server 2004/Client">
            <extend_definition comment="Microsoft Host Integration Server 2004 Client is installed" definition_ref="oval:org.mitre.oval:def:5450"/>
            <extend_definition comment="Microsoft Host Integration Server 2004 is installed" definition_ref="oval:org.mitre.oval:def:5712"/>
          </criteria>
          <criterion comment="Snarpcsv.exe version is less than 6.0.2119.0" test_ref="oval:org.mitre.oval:tst:8392"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Host Integration Server 2004/Client SP1">
          <criteria operator="OR" comment="Check for Host Integration Server 2004/Client SP1">
            <extend_definition comment="Microsoft Host Integration Server 2004 SP1 is installed" definition_ref="oval:org.mitre.oval:def:5430"/>
            <extend_definition comment="Microsoft Host Integration Server 2004 Client SP1 is installed" definition_ref="oval:org.mitre.oval:def:5939"/>
          </criteria>
          <criterion comment="Snarpcsv.exe version is less than 6.0.2430.0" test_ref="oval:org.mitre.oval:tst:9316"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Host Integration Server 2000 SP2/Administrator Client">
          <criteria operator="OR" comment="Check for Host Integration Server 2000 SP2/Administrator Client">
            <extend_definition comment="Microsoft Host Integration Server 2000 SP2 is installed" definition_ref="oval:org.mitre.oval:def:6119"/>
            <extend_definition comment="Microsoft Host Integration Server 2000 Administrator Client is installed" definition_ref="oval:org.mitre.oval:def:5472"/>
          </criteria>
          <criterion comment="Snarpcsv.exe version is less than 5.0.1.798" test_ref="oval:org.mitre.oval:tst:8893"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6119" version="4" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2000 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2000</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2000:SP2"/>
        <description>A version of Microsoft Host Integration Server 2000 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-16T16:54:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-27T10:19:55.449-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:44.927-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:12.246-05:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:54.438-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:49.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6119 - Updated CPE name" date="2011-10-21T10:13:00.283-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:27:11.117-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:05.585-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="HIServer exists as a Microsoft Host Integration Server 2000 component" test_ref="oval:org.mitre.oval:tst:9105"/>
        <criterion comment="Service Pack 2 for Microsoft Host Integration Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:8998"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5939" version="5" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2004 Client SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2004 Client</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server_client:2004:sp1"/>
        <description>A version of Microsoft Host Integration Server 2004 Client SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:44.451-04:00">DRAFT</status_change>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.283-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.937-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.453-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:37.682-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:03.320-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5939 - Several updates including updated criterias, comments and CPE names." date="2011-10-21T10:01:00.242-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:09:50.710-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:03.482-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16103 - def:6075, Edited var:620 &amp; obj:6408 to use regex &amp; match different MS HIS version directories" date="2011-11-15T14:52:00.918-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:53:31.582-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:33.947-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Host Integration Server\6.0!ProductName = Microsoft Host Integration Server 2004 Client" test_ref="oval:org.mitre.oval:tst:8770"/>
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Host Integration Server\6.0!ProductVersion = 6.0.2403.0" test_ref="oval:org.mitre.oval:tst:44390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5712" version="6" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2004 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2004</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2004:-"/>
        <description>A version of Microsoft Host Integration Server 2004 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:44.090-04:00">DRAFT</status_change>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.283-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.180-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.453-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:30.425-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:56.738-05:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:53.587-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:41.607-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5712 - Several updates including updated criterias, comments and CPE names." date="2011-10-21T10:01:00.242-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:09:50.146-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:01.630-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16103 - def:6075, Edited var:620 &amp; obj:6408 to use regex &amp; match different MS HIS version directories" date="2011-11-15T14:52:00.918-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:53:32.338-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:29.894-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Host Integration Server 2004 is installed" test_ref="oval:org.mitre.oval:tst:8356"/>
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Host Integration Server\6.0!ProductVersion = 6.0.1701.0" test_ref="oval:org.mitre.oval:tst:8892"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5472" version="3" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2000 Administrator Client is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2000 Administrator Client</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server_2000_administrator_client"/>
        <description>A version of Microsoft Host Integration Server 2000 Administrator Client is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-16T16:54:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-27T10:19:55.685-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:27.673-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:52.632-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5472 - added CPE references in several inventories for uniformity" date="2014-04-10T08:25:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:32:02.897-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:40.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Sna Server\CurrentVersion\Setup!SetupMode  = HIAdmin" test_ref="oval:org.mitre.oval:tst:8741"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5450" version="5" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2004 Client is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2004 Client</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server_client:2004:-"/>
        <description>A version of Microsoft Host Integration Server 2004 Client is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:43.846-04:00">DRAFT</status_change>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.283-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.937-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.453-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:27.337-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:51.386-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4371 - Several updates including updated criterias, comments and CPE names." date="2011-10-21T10:01:00.242-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:09:56.504-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:00.272-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16103 - def:6075, Edited var:620 &amp; obj:6408 to use regex &amp; match different MS HIS version directories" date="2011-11-15T14:52:00.918-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:53:31.254-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:26.809-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Host Integration Server\6.0!ProductName = Microsoft Host Integration Server 2004 Client" test_ref="oval:org.mitre.oval:tst:8770"/>
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Host Integration Server\6.0!ProductVersion = 6.0.1701.0" test_ref="oval:org.mitre.oval:tst:8892"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5373" version="4" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2006 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2006</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2006"/>
        <description>A version of Microsoft Host Integration Server 2006 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:43.227-04:00">DRAFT</status_change>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.045-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.198-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:26.562-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:50.571-05:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:52.167-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:35.416-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5373 - Updated CPE name" date="2011-10-21T10:13:00.283-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:27:10.002-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:59.515-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Host Integration Server 2006 is installed" test_ref="oval:org.mitre.oval:tst:9310"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6073" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14 allow Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:28.929-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:08.916-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:09.498-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:48.807-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:39.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6073 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:40.919-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:24.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10599"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6066" version="11" class="vulnerability">
      <metadata>
        <title>Apple Safari Malformed URI Remote Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0744"/>
        <description>Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (caret), (5) ` (backquote), or (6) | (pipe) character, followed by an &amp; (ampersand) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-17T12:30:50">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-03-23T10:43:52.586-04:00">DRAFT</status_change>
            <status_change date="2009-04-13T04:00:27.831-04:00">INTERIM</status_change>
            <status_change date="2009-05-04T04:00:29.145-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:28.560-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:13.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6066 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:19.441-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:34.317-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:59.573-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:07.024-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6066 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:38.232-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:46.504-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6066 - Typo Corrections" date="2014-05-22T11:01:00.943-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:03:40.377-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:44.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Safari.exe version is less than or equal to 4.528.16.0" test_ref="oval:org.mitre.oval:tst:9789"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6054" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat allows attackers to cause a denial of service via unknown vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2992"/>
        <description>An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:37.760-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:33.792-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:18.624-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:31:00.067-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:31:42.074-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:10.398-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:41.640-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:13.077-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:18.429-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:59.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:42.483-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:49.326-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:07.950-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:20.390-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6053" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14 JavaScript engine allow denial of service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3074"/>
        <description>Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:29.997-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:08.594-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:09.159-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:52.121-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:38.790-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6053 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:36.540-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:23.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10599"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6049" version="10" class="vulnerability">
      <metadata>
        <title>Wireshark Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector to cause DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3551"/>
        <description>Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:17.369-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:52.681-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:23.431-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6049 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:24.814-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:18.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5067 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:46.354-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:58.874-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:26.106-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:15.436-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6049 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:34.271-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:04.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed on the system is 1.2.0 through 1.2.2" test_ref="oval:org.mitre.oval:tst:10498"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6035" version="14" class="vulnerability">
      <metadata>
        <title>Apple iTunes Local Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3636"/>
        <description>Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys.  However, the root cause is the integer overflow in the API call itself.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-17T13:25:15">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2008-09-22T11:09:15.057-04:00">DRAFT</status_change>
            <status_change date="2008-10-13T04:00:47.085-04:00">INTERIM</status_change>
            <status_change date="2008-11-03T04:00:24.647-05:00">ACCEPTED</status_change>
            <modified comment="Updated obj:6563 to use registry key that contains the full filepath of iTunes.exe" date="2009-10-19T16:03:00.949-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-10-19T16:05:11.580-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:32.989-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:52.178-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:24.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:44.459-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:07.427-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6035 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:47.523-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:33.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:52:58.180-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:04.172-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6035 - Modified vulnerability (platforms added, extended platform definitions removed)" date="2014-01-30T14:49:00.887-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:51:09.157-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:38.549-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:51.318-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:46.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 8.0.0.35" test_ref="oval:org.mitre.oval:tst:9151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6024" version="3" class="vulnerability">
      <metadata>
        <title>Avast! Home and Professional 'aavmKer4.sys' Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3523"/>
        <description>aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:36.986-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:07.702-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:41.807-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:16.835-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:12.702-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criterion comment="Avast! version is less than 4.8.1356.0" test_ref="oval:org.mitre.oval:tst:10746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6558" version="5" class="inventory">
      <metadata>
        <title>Avast! AntiVirus for Windows is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:avast:avast_antivirus:::windows"/>
        <description>The application Avast! AntiVirus for Windows is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:37">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:36.546-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:15.773-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:53.587-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6558 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:35.733-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:23.746-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10161 - def:6558 - platform list updated, extended definitions removed, new tests for Avast" date="2014-03-26T13:20:00.160-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-26T13:22:02.443-04:00">INTERIM</status_change>
            <status_change date="2014-04-14T04:00:18.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Avast! AntiVirus old version is installed" test_ref="oval:org.mitre.oval:tst:10161"/>
        <criterion comment="Avast! AntiVirus is installed" test_ref="oval:org.mitre.oval:tst:113006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6005" version="10" class="vulnerability">
      <metadata>
        <title>Wireshark DoS Vulnerability due to the DCERPC/NT dissector</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3550"/>
        <description>The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:17.621-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:52.230-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:22.927-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6005 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:20.745-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:18.071-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5625 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:32.964-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:58.501-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:23.417-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:14.932-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6005 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:38.276-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:03.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed on the system is 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2" test_ref="oval:org.mitre.oval:tst:11016"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6001" version="12" class="vulnerability">
      <metadata>
        <title>Apple iTunes Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0016"/>
        <description>Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-17T10:31:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-03-23T10:43:53.220-04:00">DRAFT</status_change>
            <status_change date="2009-04-13T04:00:27.226-04:00">INTERIM</status_change>
            <status_change date="2009-05-04T04:00:26.020-04:00">ACCEPTED</status_change>
            <modified comment="Updated obj:6563 to use registry key that contains the full filepath of iTunes.exe" date="2009-10-19T16:03:00.949-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-10-19T16:05:11.485-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:32.259-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:49.406-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:24.106-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:41.071-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:06.964-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6001 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:46.700-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:33.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:10.814-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:03.184-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:54.796-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:46.057-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 8.1.0.51" test_ref="oval:org.mitre.oval:tst:9153"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5996" version="9" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3383"/>
        <description>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:21.381-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:14.557-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:07.377-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:00.291-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:38.286-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5996 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:39.875-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:14.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:19.840-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:11.721-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5989" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.5.x before 3.5.3 allow Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3069"/>
        <description>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:28.638-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:08.262-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:08.737-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:06.163-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:37.595-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5989 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:34.184-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:23.584-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.2" test_ref="oval:org.mitre.oval:tst:10798"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5979" version="7" class="vulnerability">
      <metadata>
        <title>Wireshark Integer overflow vulnerability in wiretap/erf.c</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3829"/>
        <description>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:17.099-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:51.297-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:22.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5979 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:18.324-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:17.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:11.051-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:14.319-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5979 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:05.379-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:02.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed on the system is before 1.2.2" test_ref="oval:org.mitre.oval:tst:10307"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5976" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark PROFINET/DCP (PN-DCP) dissector Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210"/>
        <description>Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-16T16:30:43">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-21T14:30:42.055-04:00">DRAFT</status_change>
            <status_change date="2009-05-11T04:00:30.643-04:00">INTERIM</status_change>
            <status_change date="2009-06-01T04:00:20.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:11.752-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:13.957-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5976 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:19.535-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:02.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Wireshark version is less than or equal to 1.0.6" test_ref="oval:org.mitre.oval:tst:9785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5974" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime MPEG-2 Unspecified Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0008"/>
        <description>Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:40.680-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:24.343-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:09.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:03.961-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:12.358-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:28.614-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:09.647-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5974 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:20.375-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:32.831-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5974 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:37.488-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:46.390-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5964" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat DoS or possibly execute arbitrary code via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2980"/>
        <description>Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:33.490-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:29.783-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:16.005-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:30:00.323-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:30:58.329-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:09.731-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:41.087-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:11.692-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:17.468-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:58.260-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:41.768-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:45.777-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:05.951-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:19.470-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5957" version="7" class="vulnerability">
      <metadata>
        <title>Opera integer value denial of service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2540"/>
        <description>Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T12:57:10">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-10-23T07:00:56.117-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:29.429-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:15.730-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:25.101-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:49.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5957 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:11.060-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.237-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5957 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:35.031-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:23.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera.exe version less than or equal to 9.64.10487" test_ref="oval:org.mitre.oval:tst:11114"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5955" version="7" class="vulnerability">
      <metadata>
        <title>Opera Execution of arbitrary code Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0914" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0914"/>
        <description>Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T10:31:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:10.986-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:14.468-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:25.616-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:24.501-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:48.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9724 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:09.270-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:22.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5955 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:37.049-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:23.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera version is less than 9.64 (9.64.10487.0)" test_ref="oval:org.mitre.oval:tst:9724"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5935" version="9" class="vulnerability">
      <metadata>
        <title>Remote bypass vulnerability in content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 via the document.getSelection function</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3375"/>
        <description>content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:22.840-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:14.270-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:06.853-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:07.802-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:37.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5935 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:39.768-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:14.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:17.099-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:11.538-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Mozilla Firefox Mainline version is 3.0.x to 3.0.14" test_ref="oval:org.mitre.oval:tst:120713"/>
          <criterion comment="Mozilla Firefox Mainline version is 3.5.x to 3.5.3" test_ref="oval:org.mitre.oval:tst:120990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5928" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 'keygen' HTML Tag Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1828" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1828"/>
        <description>Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T09:45:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:15.838-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:07.879-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:08.407-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:21.911-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:36.495-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5928 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:40.751-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:23.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Firefox version is equal to 3.0.10" test_ref="oval:org.mitre.oval:tst:10597"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5915" version="5" class="vulnerability">
      <metadata>
        <title>Apple Safari Local HTML Files Information Disclosure Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2842"/>
        <description>Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-17T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-17T16:08:28.996-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:00:49.822-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:20.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:35.643-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:11.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:09.523-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:06.175-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Apple Safari version is less than 5.31.21.10" test_ref="oval:org.mitre.oval:tst:10529"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5905" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2 allow Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3071"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:29.254-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:07.557-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:08.010-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:34:56.810-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:35.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5905 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:37.895-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:22.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.1 or less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10558"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5898" version="23" class="vulnerability">
      <metadata>
        <title>GDI+ TIFF Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office 2007</product>
          <product>Microsoft Office Visio 2002</product>
          <product>Microsoft Visual Studio 2008</product>
          <product>Microsoft SQL Server 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2502" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2502"/>
        <description>Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:16.991-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:27.613-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:14.299-05:00">ACCEPTED</status_change>
            <modified comment="Changed product &quot;Office 2002&quot; to &quot;Office XP&quot;" date="2010-01-14T15:39:00.296-05:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-01-14T15:39:57.302-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:14.507-05:00">ACCEPTED</status_change>
            <modified comment="Added tests for QFE versions of SQL 2005" date="2010-03-25T17:14:00.213-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-25T17:15:35.518-04:00">INTERIM</status_change>
            <modified comment="Edited var:150 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:48:00.191-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited var:309 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:48:00.238-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="Edited var:496 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:49:00.155-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:08.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12103 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:32.176-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:04.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:38.466-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:45.315-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:496 - Added closing anchors for variable regex" date="2013-04-08T11:01:00.574-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-04-08T11:03:49.596-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:32.042-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12081 - string var_check=&quot;all&quot; was replaced with var_check=&quot;at least one&quot;" date="2013-09-19T17:46:00.990-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-19T17:48:59.472-04:00">INTERIM</status_change>
            <status_change date="2013-10-07T04:11:43.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:18162 - Updating criterion logic and check attributes for Gdiplus.dll related Objects." date="2013-12-30T09:14:00.018-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-30T09:17:33.941-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:21.298-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5898 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-30T10:26:27.411-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:11:09.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5898 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:29:00.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:32:14.685-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:01:01.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable gdiplus.dll on Microsoft Windows XP x86 SP2/SP3">
          <criteria operator="OR" comment="Microsoft Windows XP x86 SP2/SP3">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="the version of gdiplus.dll is less than 5.2.6001.22319" test_ref="oval:org.mitre.oval:tst:77879"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft IE6 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Vgx.dll version is less than 6.0.2800.1637" test_ref="oval:org.mitre.oval:tst:10357"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Office XP, Project 2002, Visio 2002">
          <criteria operator="OR" comment="Microsoft Office XP, Project 2002, Visio 2002">
            <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
            <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
            <extend_definition comment="Microsoft Office Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          </criteria>
          <criterion comment="Mso.dll version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:10932"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Office 2003, Word Viewer, Excel Viewer 2003">
          <criteria operator="OR" comment="Microsoft Office 2003, Word Viewer, Excel Viewer 2003">
            <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
            <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
            <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          </criteria>
          <criterion comment="GDIPlus.dll version is less than 11.0.8312.0" test_ref="oval:org.mitre.oval:tst:10849"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Office 2007, PowerPoint Viewer 2007, Office Compatibility Pack">
          <criteria operator="OR" comment="Microsoft Office 2007, PowerPoint Viewer 2007, Office Compatibility Pack">
            <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
            <extend_definition comment="Microsoft PowerPoint Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:5517"/>
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          </criteria>
          <criterion comment="Ogl.dll version is less than 12.0.6509.5000" test_ref="oval:org.mitre.oval:tst:10022"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Visual Studio 2005">
          <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="ReportViewerLP.exe version is less than 2.0.50727.4401" test_ref="oval:org.mitre.oval:tst:10776"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Visual Studio 2008">
          <extend_definition comment="Microsoft Visual Studio 2008 is installed" definition_ref="oval:org.mitre.oval:def:5401"/>
          <criterion comment="ReportViewer.exe version is less than 9.0.21022.227" test_ref="oval:org.mitre.oval:tst:11015"/>
        </criteria>
        <criteria operator="AND" comment="SQL Server 2005 Service Pack 2">
          <criteria operator="OR" comment="Affected Software">
            <criteria operator="AND" comment="Affected Software">
              <extend_definition comment="Microsoft SQL Server 2005 is installed" definition_ref="oval:org.mitre.oval:def:6082"/>
              <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup\\SP equals 2" test_ref="oval:org.mitre.oval:tst:9558"/>
            </criteria>
            <extend_definition comment="Microsoft SQL Server 2005 SP2 is installed" definition_ref="oval:org.mitre.oval:def:8397"/>
          </criteria>
          <criteria operator="OR" comment="Affected Software">
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Database Engine - GDR">
              <criterion comment="The version of Sqlservr.exe is greater than or equal to 2005.90.3042.0" test_ref="oval:org.mitre.oval:tst:20963"/>
              <criterion comment="The version of Sqlservr.exe is less than 2005.90.3080.0" test_ref="oval:org.mitre.oval:tst:20415"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Database Engine - QFE">
              <criterion comment="The version of Sqlservr.exe is greater than or equal to 2005.90.3150.0" test_ref="oval:org.mitre.oval:tst:21221"/>
              <criterion comment="The version of Sqlservr.exe is less than 2005.90.3353.0" test_ref="oval:org.mitre.oval:tst:21128"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Analysis Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Analysis Services is installed" test_ref="oval:org.mitre.oval:tst:10937"/>
              <criterion comment="The version of Msmdsrv.exe is greater than or equal to 9.0.3042.0" test_ref="oval:org.mitre.oval:tst:21168"/>
              <criterion comment="The version of Msmdsrv.exe is less than 9.0.3080.0" test_ref="oval:org.mitre.oval:tst:10920"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Analysis Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Analysis Services is installed" test_ref="oval:org.mitre.oval:tst:10937"/>
              <criterion comment="The version of Msmdsrv.exe is greater than or equal to 9.0.3150.0" test_ref="oval:org.mitre.oval:tst:20284"/>
              <criterion comment="The version of Msmdsrv.exe is less than 9.0.3353.0" test_ref="oval:org.mitre.oval:tst:21270"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Notification Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Notification Services is installed" test_ref="oval:org.mitre.oval:tst:10812"/>
              <criterion comment="The version of Nsservice.exe is greater than or equal to 9.0.3042.0" test_ref="oval:org.mitre.oval:tst:20856"/>
              <criterion comment="The version of Nsservice.exe is less than 9.0.3080.0" test_ref="oval:org.mitre.oval:tst:10477"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Notification Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Notification Services is installed" test_ref="oval:org.mitre.oval:tst:10812"/>
              <criterion comment="The version of Nsservice.exe is greater than or equal to 9.0.3150.0" test_ref="oval:org.mitre.oval:tst:21033"/>
              <criterion comment="The version of Nsservice.exe is less than 9.0.3353.0" test_ref="oval:org.mitre.oval:tst:20413"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Reporting Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Reporting Services is installed" test_ref="oval:org.mitre.oval:tst:11011"/>
              <criterion comment="The version of Reportingservicesservice.exe is greater than or equal to 9.0.3042.0" test_ref="oval:org.mitre.oval:tst:20911"/>
              <criterion comment="The version of Reportingservicesservice.exe is less than 9.0.3080.0" test_ref="oval:org.mitre.oval:tst:10984"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Reporting Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Reporting Services is installed" test_ref="oval:org.mitre.oval:tst:11011"/>
              <criterion comment="The version of Reportingservicesservice.exe is greater than or equal to 9.0.3150.0" test_ref="oval:org.mitre.oval:tst:20529"/>
              <criterion comment="The version of Reportingservicesservice.exe is less than 9.0.3353.0" test_ref="oval:org.mitre.oval:tst:20436"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Integration Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Integration Services is installed" test_ref="oval:org.mitre.oval:tst:10380"/>
              <criterion comment="The version of Msdtssrvr.exe is greater than or equal to 9.0.3042.0" test_ref="oval:org.mitre.oval:tst:21207"/>
              <criterion comment="The version of Msdtssrvr.exe is less than 9.0.3080.0" test_ref="oval:org.mitre.oval:tst:10725"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2 Integration Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Integration Services is installed" test_ref="oval:org.mitre.oval:tst:10380"/>
              <criterion comment="The version of Msdtssrvr.exe is greater than or equal to 9.0.3150.0" test_ref="oval:org.mitre.oval:tst:21194"/>
              <criterion comment="The version of Msdtssrvr.exe is less than 9.0.3353.0" test_ref="oval:org.mitre.oval:tst:20900"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2  Tools - GDR">
              <criterion comment="Microsoft SQL Server 2005 Tools is installed" test_ref="oval:org.mitre.oval:tst:10689"/>
              <criterion comment="The version of Sqlwb.exe is greater than or equal to 2005.90.3042.0" test_ref="oval:org.mitre.oval:tst:20682"/>
              <criterion comment="The version of Sqlwb.exe is less than 2005.90.3080.0" test_ref="oval:org.mitre.oval:tst:10940"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP2  Tools - QFE">
              <criterion comment="Microsoft SQL Server 2005 Tools is installed" test_ref="oval:org.mitre.oval:tst:10689"/>
              <criterion comment="The version of Sqlwb.exe is greater than or equal to 2005.90.3150.0" test_ref="oval:org.mitre.oval:tst:21056"/>
              <criterion comment="The version of Sqlwb.exe is less than 2005.90.3353.0" test_ref="oval:org.mitre.oval:tst:21156"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="SQL Server 2005 Service Pack 3">
          <criteria operator="OR" comment="Affected Software">
            <criteria operator="AND" comment="Affected Software">
              <extend_definition comment="Microsoft SQL Server 2005 is installed" definition_ref="oval:org.mitre.oval:def:6082"/>
              <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup\\SP equals 3" test_ref="oval:org.mitre.oval:tst:10686"/>
            </criteria>
            <extend_definition comment="Microsoft SQL Server 2005 SP3 is installed" definition_ref="oval:org.mitre.oval:def:8471"/>
          </criteria>
          <criteria operator="OR" comment="Affected Software">
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Database Engine - GDR">
              <criterion comment="The version of Sqlservr.exe is greater than or equal to 2005.90.4035.0" test_ref="oval:org.mitre.oval:tst:20224"/>
              <criterion comment="The version of Sqlservr.exe is less than 2005.90.4053.0" test_ref="oval:org.mitre.oval:tst:21073"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Database Engine - QFE">
              <criterion comment="The version of Sqlservr.exe is greater than or equal to 2005.90.4207.0" test_ref="oval:org.mitre.oval:tst:21225"/>
              <criterion comment="The version of Sqlservr.exe is less than 2005.90.4262.0" test_ref="oval:org.mitre.oval:tst:20760"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Analysis Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Analysis Services is installed" test_ref="oval:org.mitre.oval:tst:10937"/>
              <criterion comment="The version of Msdtssrvr.exe is greater than or equal to 9.0.4035.0" test_ref="oval:org.mitre.oval:tst:20985"/>
              <criterion comment="The version of Msmdsrv.exe is less than 9.0.4053.0" test_ref="oval:org.mitre.oval:tst:10840"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Analysis Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Analysis Services is installed" test_ref="oval:org.mitre.oval:tst:10937"/>
              <criterion comment="The version of Msmdsrv.exe is greater than or equal to 9.0.4207.0" test_ref="oval:org.mitre.oval:tst:20435"/>
              <criterion comment="The version of Msmdsrv.exe is less than 9.0.4262.0" test_ref="oval:org.mitre.oval:tst:21171"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Notification Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Notification Services is installed" test_ref="oval:org.mitre.oval:tst:10812"/>
              <criterion comment="The version of Nsservice.exe is greater than or equal to 9.0.4035.0" test_ref="oval:org.mitre.oval:tst:21247"/>
              <criterion comment="The version of Nsservice.exe is less than 9.0.4053.0" test_ref="oval:org.mitre.oval:tst:10033"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Notification Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Notification Services is installed" test_ref="oval:org.mitre.oval:tst:10812"/>
              <criterion comment="The version of Nsservice.exe is greater than or equal to 9.0.4207.0" test_ref="oval:org.mitre.oval:tst:21170"/>
              <criterion comment="The version of Nsservice.exe is less than 9.0.4262.0" test_ref="oval:org.mitre.oval:tst:21133"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Reporting Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Reporting Services is installed" test_ref="oval:org.mitre.oval:tst:11011"/>
              <criterion comment="The version of Reportingservicesservice.exe is greater than or equal to 9.0.4035.0" test_ref="oval:org.mitre.oval:tst:21079"/>
              <criterion comment="The version of Reportingservicesservice.exe is less than 9.0.4053.0" test_ref="oval:org.mitre.oval:tst:11025"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Reporting Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Reporting Services is installed" test_ref="oval:org.mitre.oval:tst:11011"/>
              <criterion comment="The version of Reportingservicesservice.exe is greater than or equal to 9.0.4207.0" test_ref="oval:org.mitre.oval:tst:21106"/>
              <criterion comment="The version of Reportingservicesservice.exe is less than 9.0.4262.0" test_ref="oval:org.mitre.oval:tst:21137"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Integration Services - GDR">
              <criterion comment="Microsoft SQL Server 2005 Integration Services is installed" test_ref="oval:org.mitre.oval:tst:10380"/>
              <criterion comment="The version of Msdtssrvr.exe is greater than or equal to 9.0.4035.0" test_ref="oval:org.mitre.oval:tst:20985"/>
              <criterion comment="The version of Msdtssrvr.exe is less than 9.0.4053.0" test_ref="oval:org.mitre.oval:tst:10622"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3 Integration Services - QFE">
              <criterion comment="Microsoft SQL Server 2005 Integration Services is installed" test_ref="oval:org.mitre.oval:tst:10380"/>
              <criterion comment="The version of Msdtssrvr.exe is greater than or equal to 9.0.4207.0" test_ref="oval:org.mitre.oval:tst:21172"/>
              <criterion comment="The version of Msdtssrvr.exe is less than 9.0.4262.0" test_ref="oval:org.mitre.oval:tst:20876"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3  Tools - GDR">
              <criterion comment="Microsoft SQL Server 2005 Tools is installed" test_ref="oval:org.mitre.oval:tst:10689"/>
              <criterion comment="The version of Sqlwb.exe is greater than or equal to 2005.90.4035.0" test_ref="oval:org.mitre.oval:tst:20277"/>
              <criterion comment="The version of Sqlwb.exe is less than 2005.90.4053.0" test_ref="oval:org.mitre.oval:tst:10780"/>
            </criteria>
            <criteria operator="AND" comment="Microsoft SQL Server 2005 SP3  Tools - QFE">
              <criterion comment="Microsoft SQL Server 2005 Tools is installed" test_ref="oval:org.mitre.oval:tst:10689"/>
              <criterion comment="The version of Sqlwb.exe is greater than or equal to 2005.90.4207.0" test_ref="oval:org.mitre.oval:tst:20825"/>
              <criterion comment="The version of Sqlwb.exe is less than 2005.90.4262.0" test_ref="oval:org.mitre.oval:tst:20470"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8397" version="14" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2005 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft SQL Server 2005</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2005:sp2"/>
        <description>Microsoft SQL Server 2005 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-15T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-25T17:31:14.313-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:22.675-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:08.669-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11792 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:06.215-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:19.626-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11792 - SQL Server 32-bit &amp; 64-bit issues." date="2013-09-13T13:52:00.521-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:53:44.506-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:39.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26798 - &quot;MSSQL&quot; added to object regex to narrow search" date="2014-01-31T16:01:00.799-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-31T16:02:49.448-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:40.600-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26674 - Added criteria for 64 bit" date="2014-08-15T10:18:00.371-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-15T10:20:21.043-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:22.361-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26798 - Fixed/New Inventory Definitions, and fixed Vulnerability Definitions for Microsoft SQL Server 2012 and 2014." date="2014-10-10T18:35:00.565-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-10-10T19:58:53.617-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:54.506-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20846 - Modified tests which check SQL Server 2005 Service Packs. The specific version of SQL Server was checked instead of diapason. Now new states were added which mark high limit of SP and operation=&quot;greater than or equal&quot; was add to the old states" date="2014-10-29T12:41:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-29T12:42:32.067-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:02:00.209-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MS SQL Server 2005 SP2 is installed" test_ref="oval:org.mitre.oval:tst:20846"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:707" version="1" class="inventory">
      <metadata>
        <title>Microsoft Project 2002 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:project:2002:sp1"/>
        <description>The application Microsoft Project 2002 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.895-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Project Professional 2002 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:229" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows 2000 SP4 or later is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2000"/>
        <description>The operating system installed on the system is Microsoft Windows 2000 SP4 or later.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:16.978-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.885-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.915-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:11:20.008-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:40.599-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for SP4 or later and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:27.963-05:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.779-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:42.620-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:39.348-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:27.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:229 - added CPE references in several inventories for uniformity" date="2014-04-10T08:25:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:32:03.976-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:02:37.344-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:2"/>
        <criterion comment="SP4 or later Installed" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5888" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause arbitrary code execution via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2986"/>
        <description>Multiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:35.678-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:27.163-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:13.279-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:30:00.265-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:30:36.273-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:08.875-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:37.186-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:10.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:49.478-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:55.519-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:35.162-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:42.993-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:30.388-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:18.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5878" version="8" class="vulnerability">
      <metadata>
        <title>Excel Field Sanitization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Excel 2002</product>
          <product>Microsoft Excel 2003</product>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Office Excel Viewer 2003</product>
          <product>Microsoft Office Excel Viewer</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3134"/>
        <description>Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel Field Sanitization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:38.307-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:12.709-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:41.273-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6362 - Updating Microsoft Excel content to utilize the windows_view behavior." date="2012-05-10T14:07:00.113-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:24:00.007-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:01:42.869-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6918 - check the version of the file Xlview.exe when Excel Viewer 2007 is installed." date="2013-09-11T10:00:00.318-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-11T10:13:45.157-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:23.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:22.146-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:08.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="Excel.exe version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:11111"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="Excel.exe version is less than 11.0.8316.0" test_ref="oval:org.mitre.oval:tst:11073"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Excel.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:10885"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2003 is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="Xlview.exe version is less than 11.0.8313.0" test_ref="oval:org.mitre.oval:tst:11121"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Xlview.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11080"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
            <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          </criteria>
          <criterion comment="Excelcnv.exe version is less than 12.0.6514.5000" test_ref="oval:org.mitre.oval:tst:11119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:439" version="12" class="inventory">
      <metadata>
        <title>Microsoft Excel Viewer 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel Viewer 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:excel_viewer:2003"/>
        <description>The application Microsoft Excel Viewer 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:47.730-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.253-04:00">ACCEPTED</status_change>
            <modified comment="Added 2003 to the title" date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-03T04:00:37.016-05:00">INTERIM</status_change>
            <status_change date="2008-12-01T04:00:09.735-05:00">ACCEPTED</status_change>
            <modified comment="Added CPE name" date="2009-05-25T10:32:00.713-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-05-25T10:32:00.713-04:00">INTERIM</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:17.790-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6907 - Corrected several instances of invalid use of the win-def:file_object - now uses filepath entity instead of path entity and an empty filename entity." date="2011-01-31T17:34:00.117-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2011-01-31T17:38:37.445-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:49.384-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:09.772-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:19.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:439 - corrected inventory for Excel Viewer" date="2013-06-11T12:12:00.814-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:14:01.008-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:02:06.811-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:13.968-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:00.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="%ProgramFile%\Microsoft Office\OFFICE11\xlview.exe exists" test_ref="oval:org.mitre.oval:tst:9880"/>
        <criteria comment="Check if Excel Viewer">
          <criterion comment="Excel Viewer is installed." test_ref="oval:org.mitre.oval:tst:61"/>
          <criterion comment="Check if SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90840409-6000-11D3-8CFE-0150048383C9} exists" test_ref="oval:org.mitre.oval:tst:80304"/>
        </criteria>
        <criteria comment="Check if Excel Viewer 2003">
          <criterion comment="Excel Viewer 2003 is installed." test_ref="oval:org.mitre.oval:tst:9130"/>
          <criterion comment="Check if SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B025EE03392B4E348B1A777F7A5DCE16 exists" test_ref="oval:org.mitre.oval:tst:81258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5842" version="8" class="vulnerability">
      <metadata>
        <title>Null Truncation in X.509 Common Name Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2510"/>
        <description>The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:06.961-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:26.396-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:11.936-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5842 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:16:00.750-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:19:19.322-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:14.969-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.665-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.665-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:06.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5842 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.011-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:03.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msasn1.dll is less than 5.0.2195.7334" test_ref="oval:org.mitre.oval:tst:10655"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.3624" test_ref="oval:org.mitre.oval:tst:10905"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.5875" test_ref="oval:org.mitre.oval:tst:10731"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of msasn1.dll is less than 5.2.3790.4584" test_ref="oval:org.mitre.oval:tst:10013"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6000.16922" test_ref="oval:org.mitre.oval:tst:10512"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44028"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6000.21122" test_ref="oval:org.mitre.oval:tst:43659"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6001.18326" test_ref="oval:org.mitre.oval:tst:10835"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44222"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6001.22515" test_ref="oval:org.mitre.oval:tst:43926"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6002.18106" test_ref="oval:org.mitre.oval:tst:10818"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:44044"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6002.22218" test_ref="oval:org.mitre.oval:tst:44105"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.1.7600.16415" test_ref="oval:org.mitre.oval:tst:10587"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:10901"/>
              <criterion comment="the version of msasn1.dll is less than 6.1.7600.20518" test_ref="oval:org.mitre.oval:tst:10706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5822" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause Multiple Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2993"/>
        <description>The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:38.131-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:25.852-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:11.412-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:30:00.261-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:30:21.268-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:07.756-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5822 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:15.773-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:09.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:30.584-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:52.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:39.589-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:39.495-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:04.336-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:17.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5798" version="3" class="vulnerability">
      <metadata>
        <title>"SITE SET TRANSFERPROGRESS ON" FTP Command Denial of Service Vulnerability in Rhino Software Serv-U</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Rhino Software Serv-U</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3655"/>
        <description>Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:55.853-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:05.754-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:39.045-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:175 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:38.713-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:09.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Rhino Software Serv-U is installed" definition_ref="oval:org.mitre.oval:def:5875"/>
        <criterion comment="Test for Rhino Software Serv-U version is greater than or equal to 7.0.0.1" test_ref="oval:org.mitre.oval:tst:10729"/>
        <criterion comment="Test for Rhino Software Serv-U version is less than or equal to 8.2.0.3" test_ref="oval:org.mitre.oval:tst:11089"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5875" version="1" class="inventory">
      <metadata>
        <title>Rhino Software Serv-U is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Rhino Software Serv-U</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:rhinosoft:serv-u"/>
        <description>The operating system having Rhino Software Serv-U installation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:55.553-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:06.417-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:40.248-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
        </criteria>
        <criterion comment="Rhino Software Serv-U is installed" test_ref="oval:org.mitre.oval:tst:11147"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5795" version="5" class="vulnerability">
      <metadata>
        <title>DOS vulnerability in the sFlow dissector in Wireshark.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2561"/>
        <description>Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:19.991-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:07.208-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:07.640-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:29.440-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:13.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5795 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:18.867-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:01.876-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check the version of Wireshark installed is equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:10682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5777" version="9" class="vulnerability">
      <metadata>
        <title>Apple Safari WebKit Numeric Character References Remote Memory Corruption Vulnerability.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1725"/>
        <description>WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T09:00:11">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:37:10.113-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:06.562-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:06.971-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:31.173-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:09.181-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5777 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:24.394-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:32.415-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:07:03.463-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:05.438-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5777 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:37.933-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:45.713-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Safari.exe version is less than 4.530.19.1 (4.0.2)" test_ref="oval:org.mitre.oval:tst:10617"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5768" version="8" class="vulnerability">
      <metadata>
        <title>Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office PowerPoint Viewer 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0120"/>
        <description>Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:00.590-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:07.155-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:31.250-04:00">ACCEPTED</status_change>
            <modified comment="the comment for tst:8340 has been updated to reflect the correct version" date="2008-10-27T09:35:00.270-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-10-27T09:38:03.457-04:00">INTERIM</status_change>
            <status_change date="2008-11-17T04:00:33.740-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5768 - def:5768, &quot;Removed all not required criterion's &amp; added only for PowerPoint Viewer 2003&quot;. def:5724, &quot;Removed all not required criterion's &amp; added only for PowerPoint Viewer 2003&quot;. def:5555, &quot;Removed PowerPoint Viewer 2003 criteria, which is not affected&quot;" date="2011-10-17T09:28:00.566-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-10-17T09:35:10.104-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:02.577-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:44.326-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:35.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:06.225-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:05.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
        <criterion comment="the version of Pptview.exe is less than 11.0.8164.0" test_ref="oval:org.mitre.oval:tst:9044"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5757" version="3" class="vulnerability">
      <metadata>
        <title>Pidgin 2.6.0 and prior does not follow the require TLS/SSL preference</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Pidgin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026"/>
        <description>protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T03:13:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:36:44.202-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:06.190-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:06.614-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10807 - number of updates and additions for Pidgin on Windows" date="2013-08-22T10:34:00.589-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-08-22T10:37:19.551-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:03:41.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Pidgin is installed" definition_ref="oval:org.mitre.oval:def:12366"/>
        <criterion comment="Pidgin version is less than or equal to 2.6.0" test_ref="oval:org.mitre.oval:tst:10807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5748" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark Tektronix .rf5 Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1269"/>
        <description>Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-16T16:30:43">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-21T14:30:44.236-04:00">DRAFT</status_change>
            <status_change date="2009-05-11T04:00:21.923-04:00">INTERIM</status_change>
            <status_change date="2009-06-01T04:00:18.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:34.364-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:13.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5748 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:36.415-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:01.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Version of Wireshark is 0.99.6 through 1.0.6" test_ref="oval:org.mitre.oval:tst:81303"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5724" version="8" class="vulnerability">
      <metadata>
        <title>Memory Calculation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office PowerPoint Viewer 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0121"/>
        <description>A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:06.907-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:04.633-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:29.400-04:00">ACCEPTED</status_change>
            <modified comment="the comment for tst:8340 has been updated to reflect the correct version" date="2008-10-27T09:35:00.270-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-10-27T09:38:03.599-04:00">INTERIM</status_change>
            <status_change date="2008-11-17T04:00:31.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5724 - def:5768, &quot;Removed all not required criterion's &amp; added only for PowerPoint Viewer 2003&quot;. def:5724, &quot;Removed all not required criterion's &amp; added only for PowerPoint Viewer 2003&quot;. def:5555, &quot;Removed PowerPoint Viewer 2003 criteria, which is not affected&quot;" date="2011-10-17T09:28:00.566-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-10-17T09:35:10.740-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:01.962-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:17.452-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:33.469-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:15.434-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:05.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
        <criterion comment="the version of Pptview.exe is less than 11.0.8164.0" test_ref="oval:org.mitre.oval:tst:9044"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6014" version="6" class="inventory">
      <metadata>
        <title>Microsoft PowerPoint Viewer is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:powerpoint_viewer"/>
        <description>The application Microsoft PowerPoint Viewer is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:59.590-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:22.609-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:39.579-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:53.300-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:46.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:47:20.412-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:57.005-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:55:59.839-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:12.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft PowerPoint Viewer is installed." test_ref="oval:org.mitre.oval:tst:9134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5722" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player before 11.5.2.602 allows arbitrary Code Execution invalid pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3465"/>
        <description>Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T08:55:31.430-04:00">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:38.870-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:39.214-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:27.778-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:08.495-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:31.292-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="check for the version Adobe shockwave player" test_ref="oval:org.mitre.oval:tst:10555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5719" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat getPlus_HelperSvc.exe) local elevation of privileges</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2564"/>
        <description>NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:32.781-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:22.796-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:08.474-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:29:00.764-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:30:00.771-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:07.211-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:34.891-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:08.499-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:26.804-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:50.777-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:32.408-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:35.896-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:24.472-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:16.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5717" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2 allow multiple DOS Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075"/>
        <description>Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:30.414-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:05.809-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:06.233-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:36:00.565-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:34.822-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5717 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:38.622-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:22.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.1 or less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10558"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5716" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework Pointer Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0090"/>
        <description>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:55.227-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:21.996-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:07.631-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:44.235-05:00">INTERIM</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:00:00.766-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.229-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.547-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-21T04:00:37.997-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5716 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:02.153-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:52.645-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.368-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.368-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:05.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5716 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:18.399-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:01.746-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 1.1 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of Mscorlib.dll is less than 1.1.4322.2443" test_ref="oval:org.mitre.oval:tst:10854"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5677" version="3" class="vulnerability">
      <metadata>
        <title>Adobe Shockwave Player before 11.5.2.602 allows Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Adobe Shockwave Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3463" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3463"/>
        <description>Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T08:55:31.430-04:00">
              <contributor organization="SecPod Technologies">Antu Sanadi</contributor>
            </submitted>
            <status_change date="2009-11-30T14:34:38.479-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:00:36.491-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:26.217-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7257 - For 64-bit systems, all files are placed in syswow64-branch. And also check=&quot;all&quot; was replaced on check=&quot;at least one&quot; in tests." date="2014-10-24T13:15:00.008-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-24T13:17:07.937-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:31.048-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Adobe Shockwave Player is installed" definition_ref="oval:org.mitre.oval:def:5990"/>
        <criterion comment="check for the version Adobe shockwave player" test_ref="oval:org.mitre.oval:tst:10555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5672" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime before 7.6.4 allows Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2203"/>
        <description>Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T10:30:41">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:34.674-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:05.235-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:05.582-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:09.678-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:08.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:37.670-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:08.381-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5672 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:54.513-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:31.923-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5672 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:39.145-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:45.587-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.4 (7.64.17.73)" test_ref="oval:org.mitre.oval:tst:10538"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5646" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime QTVR Heap Based buffer overflow vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0002"/>
        <description>Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T10:10:10">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:41.058-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:21.449-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:09.130-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:03.690-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:07.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:40.361-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:07.921-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5646 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:43:48.580-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:31.477-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5646 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:39.584-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:45.418-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.60.92.0" test_ref="oval:org.mitre.oval:tst:8919"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5636" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause DoS (memory corruption) or execute arbitrary code via unspecified vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2983"/>
        <description>Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:34.633-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:21.547-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:07.165-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:29:00.189-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:29:39.196-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:06.167-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:38.803-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:07.165-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:27.707-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:47.332-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:37.318-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:32.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:00.612-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:16.152-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5625" version="5" class="vulnerability">
      <metadata>
        <title>DOS vulnerability in the AFS dissector in Wireshark.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562"/>
        <description>Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:20.435-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:04.823-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:05.209-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:21.452-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:12.743-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5625 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:45.833-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:05:00.338-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed is less than or equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:9842"/>
        <criterion comment="Check for version of Wireshark installed is greater than or equal to 0.9.2" test_ref="oval:org.mitre.oval:tst:10358"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5606" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3 allow dangling pointer vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3077"/>
        <description>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:30.877-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:04.489-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:04.799-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:39.787-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:34.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5606 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:36.044-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:22.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.2 or less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5581" version="9" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox 3.0.x before 3.0.15 cause a denial of service in layout/base/nsCSSFrameConstructor.cpp</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382"/>
        <description>layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-04T12:10:11">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2009-11-04T15:47:21.636-05:00">DRAFT</status_change>
            <status_change date="2009-11-23T04:00:13.464-05:00">INTERIM</status_change>
            <status_change date="2009-12-14T04:00:05.415-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:59.252-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:33.394-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5581 - fixes to Mozilla definitions" date="2014-07-31T11:40:00.021-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-31T11:42:36.331-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - Added case insensitve equals" date="2014-08-13T10:32:00.179-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-01T04:03:14.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:30212 - critical fixes to objects 30212, 30018, 29411 and 29644" date="2014-09-17T10:11:00.267-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-09-17T10:16:19.620-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:04:11.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox Mainline version is 3.0.x to 3.0.14" test_ref="oval:org.mitre.oval:tst:120713"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5560" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat memory corruption or possibly execute arbitrary code via unspecified vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2996" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2996"/>
        <description>Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2985.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:39.289-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:19.943-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:04.915-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:28:00.441-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:29:18.448-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:05.481-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:47.694-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:06.520-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:41.128-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:44.870-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:49.564-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:28.284-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:51.830-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:15.139-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5559" version="9" class="vulnerability">
      <metadata>
        <title>Apple Safari Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple Safari</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1233"/>
        <description>Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-07T09:10:59">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:32.015-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:08.999-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:21.610-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:24 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:29:12.696-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:06.195-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5559 - The attached file Apple Safari.xml contains modified vulnerabilities." date="2013-07-12T15:28:00.438-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:39:28.904-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:31.046-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6703 - Added check in 32-bit registry branch to obj:6703" date="2013-10-17T12:04:00.452-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-10-17T12:06:36.821-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:04.623-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5559 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:38.673-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:45.241-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple Safari is installed" definition_ref="oval:org.mitre.oval:def:6325"/>
        <criterion comment="Safari.exe version is less than or equal to 4.528.16.0" test_ref="oval:org.mitre.oval:tst:9531"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5557" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat might allow remote attackers to execute arbitrary code via unknown vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2991" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2991"/>
        <description>Unspecified vulnerability in the Mozilla plug-in in Adobe Reader and Acrobat 8.x before 8.1.7, and possibly 7.x before 7.1.4 and 9.x before 9.2, might allow remote attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:37.402-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:19.539-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:04.405-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:28:00.757-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:28:54.763-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:04.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:39.392-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:05.527-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:49:29.322-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:41.631-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:38.699-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:26.850-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:02.792-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:14.292-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5555" version="9" class="vulnerability">
      <metadata>
        <title>Parsing Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Compatibility Pack</product>
          <product>Microsoft Office PowerPoint 2000</product>
          <product>Microsoft Office PowerPoint 2002</product>
          <product>Microsoft Office PowerPoint 2003</product>
          <product>Microsoft Office PowerPoint 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1455" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1455"/>
        <description>A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 through SP1; and Office 2004 for Mac allows remote attackers to execute arbitrary code via a PowerPoint file with crafted list values that trigger memory corruption, aka "Parsing Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:11.421-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:58.427-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:24.287-04:00">ACCEPTED</status_change>
            <modified comment="the comment for tst:8340 has been updated to reflect the correct version" date="2008-10-27T09:35:00.270-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-10-27T09:38:03.737-04:00">INTERIM</status_change>
            <status_change date="2008-11-17T04:00:28.897-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5555 - def:5768, &quot;Removed all not required criterion's &amp; added only for PowerPoint Viewer 2003&quot;. def:5724, &quot;Removed all not required criterion's &amp; added only for PowerPoint Viewer 2003&quot;. def:5555, &quot;Removed PowerPoint Viewer 2003 criteria, which is not affected&quot;" date="2011-10-17T09:28:00.566-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-10-17T09:35:11.563-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:00.609-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:850 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:45.793-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-06-04T04:01:26.149-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - Modified criteria to match MS bulletin" date="2014-06-13T14:52:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T14:56:14.282-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:02.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="PowerPoint 2000">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of powerpnt.exe is less than 9.0.0.8969" test_ref="oval:org.mitre.oval:tst:9017"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2002">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of powerpnt.exe is less than 10.0.6842.0" test_ref="oval:org.mitre.oval:tst:8929"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2003">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8227.0" test_ref="oval:org.mitre.oval:tst:8173"/>
        </criteria>
        <criteria operator="AND" comment="PowerPoint 2007">
          <extend_definition comment="Microsoft PowerPoint 2007 is installed" definition_ref="oval:org.mitre.oval:def:5937"/>
          <criterion comment="the version of powerpnt.exe is less than 12.0.6300.5000" test_ref="oval:org.mitre.oval:tst:8340"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="the version of pptcnv.dll is less than 12.0.6320.5000" test_ref="oval:org.mitre.oval:tst:8980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:696" version="7" class="inventory">
      <metadata>
        <title>Microsoft PowerPoint 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint 2000</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:powerpoint:2000"/>
        <description>The application Microsoft PowerPoint 2000 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.533-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.039-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference" date="2007-05-01T10:21:00.110-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-01T10:23:06.132-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:51.176-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft PowerPoint 2000 to list of affected products. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:01:06.176-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:01:09.558-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:696 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:42.261-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:42.358-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:649 - Updating Microsoft PowerPoint registry locations." date="2012-05-10T14:25:00.252-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-05-10T14:37:52.449-04:00">INTERIM</status_change>
            <status_change date="2012-05-28T04:02:18.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="PowerPoint 2000 is installed" test_ref="oval:org.mitre.oval:tst:861"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5523" version="16" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat cause denial of service or possibly execute arbitrary code via unknown vectors</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
          <product>Adobe Acrobat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2984"/>
        <description>Unspecified vulnerability in the image decoder in Adobe Acrobat 9.x before 9.2, and possibly 7.x through 7.1.4 and 8.x through 8.1.7, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:34.959-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:19.125-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:03.587-05:00">ACCEPTED</status_change>
            <modified comment="Add adobe reader and acrobat 7.0, check for library version 7.1.4. Add adobe reader and acrobat 8.0, check for library version 8.1.7. Add adobe reader and acrobat 9.0, check for library version 9.2.0." date="2010-01-07T13:27:00.330-05:00">
              <contributor organization="Marandel.net">Benjamin Marandel</contributor>
            </modified>
            <status_change date="2010-01-07T13:28:05.336-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:04.219-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20819 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:38:48.877-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:832 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-22T04:01:04.810-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7175 - Fix to Adobe Reader 9 Inventory Definition to return false when not installed instead of error." date="2012-12-27T23:44:00.907-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2012-12-27T23:50:04.170-05:00">INTERIM</status_change>
            <status_change date="2013-01-14T04:02:39.249-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7253 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:51.115-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6272 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:35:00.332-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7189 - Updates to Adobe Acrobat and Reader on Windows to return false rather than error on several checks. New Inventory and Vulnerability Definitions for Reader and Acrobat." date="2013-01-22T14:48:00.343-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-02-11T04:02:25.497-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7375 - added check for 32\64-bit registry branche" date="2013-07-26T10:50:00.323-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T10:53:52.628-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7376 - added check for 32\64-bit registry branche" date="2013-07-26T10:53:00.574-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7190 - added check for 32\64-bit registry branche" date="2013-07-26T10:58:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:7398 - added check for 32\64-bit registry branche" date="2013-07-26T11:02:00.428-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-12T04:09:13.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Adobe Reader 7">
          <extend_definition comment="Adobe Reader 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6377"/>
          <criteria operator="OR" comment="Adobe Reader 7, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10750"/>
            <criterion comment="Adobe Reader library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20520"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 8">
          <extend_definition comment="Adobe Reader 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6390"/>
          <criteria operator="OR" comment="Adobe Reader 8, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11069"/>
            <criterion comment="Adobe Reader library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20592"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Reader 9">
          <extend_definition comment="Adobe Reader 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6523"/>
          <criteria operator="OR" comment="Adobe Reader 9, the sub-version is vulnerable">
            <criterion comment="Adobe Reader is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:10915"/>
            <criterion comment="Adobe Reader library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 7">
          <extend_definition comment="Adobe Acrobat 7 Series is installed" definition_ref="oval:org.mitre.oval:def:6213"/>
          <criteria operator="OR" comment="Adobe Acrobat 7, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 7.1.4" test_ref="oval:org.mitre.oval:tst:10911"/>
            <criterion comment="Adobe Acrobat library is less than 7.1.4.2009100300" test_ref="oval:org.mitre.oval:tst:20163"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 8">
          <extend_definition comment="Adobe Acrobat 8 Series is installed" definition_ref="oval:org.mitre.oval:def:6452"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 8.1.7" test_ref="oval:org.mitre.oval:tst:11087"/>
            <criterion comment="Adobe Acrobat library is less than 8.1.7.59" test_ref="oval:org.mitre.oval:tst:20962"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Adobe Acrobat 9">
          <extend_definition comment="Adobe Acrobat 9 Series is installed" definition_ref="oval:org.mitre.oval:def:6013"/>
          <criteria operator="OR" comment="Adobe Acrobat 8, the sub-version is vulnerable">
            <criterion comment="Adobe Acrobat is less than 9.2.0" test_ref="oval:org.mitre.oval:tst:11017"/>
            <criterion comment="Adobe Acrobat library is less than 9.1.0.2009022700" test_ref="oval:org.mitre.oval:tst:20659"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6377" version="7" class="inventory">
      <metadata>
        <title>Adobe Reader 7 Series is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Adobe Reader</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:adobe:reader:7"/>
        <description>Adobe Reader 7 Series is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-23T03:25:55">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-10-23T15:03:30.438-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:52.128-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:36.573-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6377 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:39.995-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:39.196-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5564 - Updated criterion comments to align with test comments, corrected version numbers in test comments, changed numerous occurrences of 'Reader' to 'Acrobat', added '$' to the end of regular expressions, removed duplicate variables and objects, and removed trailing '\' from paths." date="2011-08-01T07:18:00.114-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-01T07:40:12.173-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:24.447-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6377 - Fix to Adobe Reader 7,8,10 Inventory Definitions to return false when not installed instead of error." date="2013-01-22T14:31:00.389-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-01-22T14:35:11.507-05:00">INTERIM</status_change>
            <status_change date="2013-02-11T04:03:08.163-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Adobe Reader 7.x version is installed" test_ref="oval:org.mitre.oval:tst:10977"/>
        <criterion comment="Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Acrobat Reader\7.0\Installer!ENU_GUID exists" test_ref="oval:org.mitre.oval:tst:80693"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5467" version="9" class="vulnerability">
      <metadata>
        <title>Apple QuickTime before 7.6.4 allows to execute arbitrary code or DOS Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Apple QuickTime</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2202"/>
        <description>Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T10:30:41">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:34.460-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:03.714-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:03.986-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:11.493-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:04.439-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:92 - New Vulnerability Definitions for QuickTime for Windows." date="2012-12-12T18:08:00.964-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-12-12T18:37:48.979-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:02:07.490-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5467 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:40:00.496-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T15:44:11.546-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:30.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5467 - platforms were added and extended definitions were removed" date="2014-01-16T10:42:00.100-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-16T10:44:39.746-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:44.971-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple QuickTime is installed" definition_ref="oval:org.mitre.oval:def:12443"/>
        <criterion comment="QuickTimePlayer.exe version is less than 7.6.4 (7.64.17.73)" test_ref="oval:org.mitre.oval:tst:10538"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5432" version="7" class="vulnerability">
      <metadata>
        <title>Opera Web Browser Denial Of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Opera Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1234"/>
        <description>Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags.  NOTE: it was later reported that 9.52 is also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-07T08:55:31.430-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:33.645-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:07.630-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:20.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:309 - New Microsoft Patch Tuesday May 2012 definitions." date="2012-05-18T15:40:00.554-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-05-18T15:48:27.310-04:00">INTERIM</status_change>
            <status_change date="2012-06-04T04:01:23.414-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9794 - Now path to opera.exe is searched in registry" date="2013-12-04T13:48:00.075-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-04T13:53:08.862-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:01:21.994-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5432 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:34.692-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:21.023-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Opera Browser is installed" definition_ref="oval:org.mitre.oval:def:6482"/>
        <criterion comment="Opera version is less than or equla to 9.64 (9.64.10487.0)" test_ref="oval:org.mitre.oval:tst:9794"/>
        <criterion comment="Check if HKLM\SOFTWARE\Classes\Applications\Opera.exe\shell\open\command exists" test_ref="oval:org.mitre.oval:tst:89007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5423" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark, which triggers an assertion failure.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3242"/>
        <description>Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-24T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-24T22:35:18.724-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:03.361-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:03.597-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:34.903-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:12.363-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5423 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:43:33.723-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:04:59.888-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed less than or equal to 1.2.1" test_ref="oval:org.mitre.oval:tst:10713"/>
        <criterion comment="Check the version of Wireshark installed greater than or equal to 1.2.0" test_ref="oval:org.mitre.oval:tst:10735"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5418" version="6" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3 allow Visual truncation vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3078"/>
        <description>Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T12:10:11">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-09-23T12:26:31.176-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:02.812-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:03.244-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Adding the '&lt;behaviors windows_view=&quot;32_bit&quot; />' for oval:org.mitre.oval:obj:6886." date="2013-05-07T09:28:00.207-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-05-07T09:35:12.461-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6886 - Fixed Firefox version comparison" date="2013-05-15T14:51:00.342-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-03T04:03:32.720-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5418 - fixed vulnerabilities with added extend definitions" date="2014-02-26T15:19:00.077-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-26T15:21:40.007-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:20.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Mozilla Firefox Mainline release is installed" definition_ref="oval:org.mitre.oval:def:22259"/>
        <criterion comment="Mozilla Firefox version 3.5.x to 3.5.2 or less than 3.0.14" test_ref="oval:org.mitre.oval:tst:10722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5336" version="12" class="vulnerability">
      <metadata>
        <title>Apple iTunes Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Apple iTunes</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0143"/>
        <description>Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-17T10:31:31">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-03-23T10:43:56.417-04:00">DRAFT</status_change>
            <status_change date="2009-04-13T04:00:20.933-04:00">INTERIM</status_change>
            <status_change date="2009-05-04T04:00:10.093-04:00">ACCEPTED</status_change>
            <modified comment="Updated obj:6563 to use registry key that contains the full filepath of iTunes.exe" date="2009-10-19T16:03:00.949-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-10-19T16:05:11.352-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:17.536-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Added new definition for CVE-2011-0152, and changed the iTunes registry test to check for the Windows registered shell command path" date="2011-03-16T10:55:00.013-04:00">
              <contributor organization="Quintechssential">Scott Quint</contributor>
            </modified>
            <status_change date="2011-03-16T11:03:48.816-04:00">INTERIM</status_change>
            <status_change date="2011-04-04T04:00:23.598-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - Modified obj:15953 to pick the default registry path for all iTunes versions." date="2012-01-04T16:31:00.380-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2012-01-04T16:33:40.386-05:00">INTERIM</status_change>
            <status_change date="2012-01-23T04:03:06.533-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5336 - The attached files Apple QuickTime.xml and Apple iTunes.xml contain modified vulnerabilities." date="2013-07-12T15:54:00.483-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-12T16:09:45.085-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:01:29.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15953 - a bunch of new definitions for iTunes CVEs on Windows" date="2013-07-31T10:49:00.886-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T15:53:23.468-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:04:59.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:282 - Corrected iTunes 12 registry path" date="2015-06-02T13:51:00.209-04:00">
              <contributor organization="baramundi software">Bernd Eggenmueller</contributor>
            </modified>
            <status_change date="2015-06-02T13:53:58.000-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:45.793-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Apple iTunes is installed" definition_ref="oval:org.mitre.oval:def:12353"/>
        <criterion comment="iTunes.exe version is less than 8.1.0.51" test_ref="oval:org.mitre.oval:tst:9153"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5335" version="5" class="vulnerability">
      <metadata>
        <title>Wireshark CPHAP dissector Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1268"/>
        <description>The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-16T16:30:43">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </submitted>
            <status_change date="2009-04-21T14:30:44.822-04:00">DRAFT</status_change>
            <status_change date="2009-05-11T04:00:18.565-04:00">INTERIM</status_change>
            <status_change date="2009-06-01T04:00:09.076-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6871 - New Wireshark vulnerability definitions. Simplified criteria for existing Wireshark vulnerability definitions." date="2012-02-29T14:32:00.864-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-02-29T15:57:21.758-05:00">INTERIM</status_change>
            <status_change date="2012-03-19T04:01:11.945-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5335 - new definitions for the latest Wireshark CVEs on Windows" date="2013-07-31T16:06:00.927-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-07-31T16:42:51.860-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:04:58.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Version of Wireshark is 0.9.6 through 1.0.6" test_ref="oval:org.mitre.oval:tst:81218"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29525" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Excel DLL remote code execution vulnerability - CVE-2015-2378 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Excel 2010</product>
          <product>Microsoft Excel Viewer 2007</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2378"/>
        <description>Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:43.045-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:58.182-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:28.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Excel 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Check if the version of excel.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:140929"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2010 is installed" definition_ref="oval:org.mitre.oval:def:12658"/>
          <criterion comment="Check if the version of excel.exe is less than 14.0.7153.5000" test_ref="oval:org.mitre.oval:tst:141097"/>
        </criteria>
        <criteria operator="AND" comment="Excel Viewer and vulnerable file version">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Check if the version of xlview.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:141331"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007 and vulnerable version">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="Check if the version of excelcnv.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:140850"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29517" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability - CVE-2015-2424 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft PowerPoint 2007</product>
          <product>Microsoft PowerPoint 2010</product>
          <product>Microsoft PowerPoint 2013</product>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Word 2010</product>
          <product>Microsoft Word 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2424"/>
        <description>Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:48.207-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.804-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:28.167-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Powerpoint 2007 and vulnerable file version">
          <extend_definition comment="Microsoft PowerPoint 2007 is installed" definition_ref="oval:org.mitre.oval:def:5937"/>
          <criterion comment="Check if the version of ppcore.dll is less than 12.0.6726.5000" test_ref="oval:org.mitre.oval:tst:141384"/>
        </criteria>
        <criteria operator="AND" comment="Powerpoint 2010 and vulnerable file version">
          <extend_definition comment="Microsoft PowerPoint 2010 is installed" definition_ref="oval:org.mitre.oval:def:12376"/>
          <criterion comment="Check if the version of ppcore.dll is less than 14.0.7153.5002" test_ref="oval:org.mitre.oval:tst:140844"/>
        </criteria>
        <criteria operator="AND" comment="Powerpoint 2013 and vulnerable file version">
          <extend_definition comment="Microsoft PowerPoint 2013 is installed" definition_ref="oval:org.mitre.oval:def:15696"/>
          <criterion comment="Check if the version ppcore.dll is less than 15.0.4737.1003" test_ref="oval:org.mitre.oval:tst:141320"/>
        </criteria>
        <criteria operator="AND" comment="Word 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="Check if the version of winword.exe is less than 12.0.6726.5000" test_ref="oval:org.mitre.oval:tst:141290"/>
        </criteria>
        <criteria operator="AND" comment="Word 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2010 is installed" definition_ref="oval:org.mitre.oval:def:7631"/>
          <criterion comment="Check if the version of winword.exe is less than 14.0.7153.5002" test_ref="oval:org.mitre.oval:tst:141421"/>
        </criteria>
        <criteria operator="AND" comment="Word 2013  and vulnerable file version">
          <extend_definition comment="Microsoft Word 2013 is installed" definition_ref="oval:org.mitre.oval:def:15560"/>
          <criterion comment="Check if the version of winword.exe is less than 15.0.4737.1003" test_ref="oval:org.mitre.oval:tst:141304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29493" version="3" class="vulnerability">
      <metadata>
        <title>OpenType font driver vulnerability - CVE-2015-2426 (MS15-078)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2426"/>
        <description>Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:33:46.957-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.541-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:28.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.243" test_ref="oval:org.mitre.oval:tst:141149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29487" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2388 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-2388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2388" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1738.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:53.088-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.248-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:27.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29485" version="3" class="vulnerability">
      <metadata>
        <title>SQL Server remote code execution vulnerability - CVE-2015-1762 (MS15-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft SQL Server 2008</product>
          <product>Microsoft SQL Server 2008 R2</product>
          <product>Microsoft SQL Server 2012</product>
          <product>Microsoft SQL Server 2014</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1762"/>
        <description>Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not prevent use of uninitialized memory in unspecified function calls, which allows remote authenticated users to execute arbitrary code by leveraging certain permissions and making a crafted query, as demonstrated by the VIEW SERVER STATE permission, aka "SQL Server Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:09:50.375-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.044-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:27.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft SQL Server 2008 and vulnerable file version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2008 is installed" definition_ref="oval:org.mitre.oval:def:12454"/>
            <extend_definition comment="Microsoft SQL Server 2008 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15497"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.5538.0" test_ref="oval:org.mitre.oval:tst:140857"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.0.5750.0" test_ref="oval:org.mitre.oval:tst:121683"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.5890.0" test_ref="oval:org.mitre.oval:tst:140253"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2008 Service Pack 4 is installed" definition_ref="oval:org.mitre.oval:def:28999"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.6535.0" test_ref="oval:org.mitre.oval:tst:141246"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.0.6500.0" test_ref="oval:org.mitre.oval:tst:141186"/>
            </criteria>
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.6241.0" test_ref="oval:org.mitre.oval:tst:141140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12596"/>
            <extend_definition comment="Microsoft SQL Server 2008 R2 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15803"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.4042.0" test_ref="oval:org.mitre.oval:tst:140756"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.50.4251" test_ref="oval:org.mitre.oval:tst:122178"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.4339.0" test_ref="oval:org.mitre.oval:tst:141132"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 R2 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2008 R2 SP3 is installed" definition_ref="oval:org.mitre.oval:def:28713"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.6220.0" test_ref="oval:org.mitre.oval:tst:140888"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.6529.0" test_ref="oval:org.mitre.oval:tst:140717"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.50.6500.0" test_ref="oval:org.mitre.oval:tst:140270"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2012 vulnerable version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:15044"/>
            <extend_definition comment="Microsoft SQL Server 2012 SP1 is installed" definition_ref="oval:org.mitre.oval:def:21029"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.3156.0" test_ref="oval:org.mitre.oval:tst:141009"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 11.0.3300" test_ref="oval:org.mitre.oval:tst:122379"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.3513.0" test_ref="oval:org.mitre.oval:tst:141172"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2012 vulnerable version">
          <extend_definition comment="Microsoft SQL Server 2012 SP2 is installed" definition_ref="oval:org.mitre.oval:def:29429"/>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.5343.0" test_ref="oval:org.mitre.oval:tst:141193"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.5613.0" test_ref="oval:org.mitre.oval:tst:141079"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 11.0.5600.0" test_ref="oval:org.mitre.oval:tst:141019"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2014 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2014 is installed" definition_ref="oval:org.mitre.oval:def:26140"/>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 12.0.2269.0" test_ref="oval:org.mitre.oval:tst:141088"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 12.0.2300" test_ref="oval:org.mitre.oval:tst:122271"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 12.0.2548.0" test_ref="oval:org.mitre.oval:tst:141078"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29480" version="2" class="vulnerability">
      <metadata>
        <title>Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code (CVE-2006-5857)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Acrobat</product>
          <product>Adobe Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5857"/>
        <description>Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-30T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-07-31T12:47:21.289-04:00">DRAFT</status_change>
            <status_change date="2015-08-17T04:01:41.726-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check version of Acrobat">
          <extend_definition comment="Adobe Acrobat is installed" definition_ref="oval:org.mitre.oval:def:28344"/>
          <criterion comment="Check if the version of Adobe Acrobat is less than 7.0.8" test_ref="oval:org.mitre.oval:tst:141217"/>
        </criteria>
        <criteria operator="AND" comment="Check version of Reader">
          <extend_definition comment="Adobe Reader is installed" definition_ref="oval:org.mitre.oval:def:27788"/>
          <criterion comment="Check if the version of Adobe Reader is less than 7.0.8" test_ref="oval:org.mitre.oval:tst:141155"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29470" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2414 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2414" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:13.594-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.809-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:27.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29454" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-2402 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2402" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:58.714-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.432-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:26.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29452" version="3" class="vulnerability">
      <metadata>
        <title>SQL Server elevation of privilege vulnerability - CVE-2015-1761 (MS15-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft SQL Server 2008</product>
          <product>Microsoft SQL Server 2008 R2</product>
          <product>Microsoft SQL Server 2012</product>
          <product>Microsoft SQL Server 2014</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1761"/>
        <description>Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authenticated users to gain privileges by leveraging certain write access, aka "SQL Server Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:09:54.939-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.171-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:26.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft SQL Server 2008 and vulnerable file version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2008 is installed" definition_ref="oval:org.mitre.oval:def:12454"/>
            <extend_definition comment="Microsoft SQL Server 2008 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15497"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.5538.0" test_ref="oval:org.mitre.oval:tst:140857"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.0.5750.0" test_ref="oval:org.mitre.oval:tst:121683"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.5890.0" test_ref="oval:org.mitre.oval:tst:140253"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2008 Service Pack 4 is installed" definition_ref="oval:org.mitre.oval:def:28999"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.6535.0" test_ref="oval:org.mitre.oval:tst:141246"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.0.6500.0" test_ref="oval:org.mitre.oval:tst:141186"/>
            </criteria>
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.6241.0" test_ref="oval:org.mitre.oval:tst:141140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12596"/>
            <extend_definition comment="Microsoft SQL Server 2008 R2 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15803"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.4042.0" test_ref="oval:org.mitre.oval:tst:140756"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.50.4251" test_ref="oval:org.mitre.oval:tst:122178"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.4339.0" test_ref="oval:org.mitre.oval:tst:141132"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 R2 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2008 R2 SP3 is installed" definition_ref="oval:org.mitre.oval:def:28713"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.6220.0" test_ref="oval:org.mitre.oval:tst:140888"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.6529.0" test_ref="oval:org.mitre.oval:tst:140717"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.50.6500.0" test_ref="oval:org.mitre.oval:tst:140270"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2012 vulnerable version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:15044"/>
            <extend_definition comment="Microsoft SQL Server 2012 SP1 is installed" definition_ref="oval:org.mitre.oval:def:21029"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.3156.0" test_ref="oval:org.mitre.oval:tst:141009"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 11.0.3300" test_ref="oval:org.mitre.oval:tst:122379"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.3513.0" test_ref="oval:org.mitre.oval:tst:141172"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2012 vulnerable version">
          <extend_definition comment="Microsoft SQL Server 2012 SP2 is installed" definition_ref="oval:org.mitre.oval:def:29429"/>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.5343.0" test_ref="oval:org.mitre.oval:tst:141193"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.5613.0" test_ref="oval:org.mitre.oval:tst:141079"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 11.0.5600.0" test_ref="oval:org.mitre.oval:tst:141019"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2014 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2014 is installed" definition_ref="oval:org.mitre.oval:def:26140"/>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 12.0.2269.0" test_ref="oval:org.mitre.oval:tst:141088"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 12.0.2300" test_ref="oval:org.mitre.oval:tst:122271"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 12.0.2548.0" test_ref="oval:org.mitre.oval:tst:141078"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29449" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability - CVE-2015-2380 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Word Viewer</product>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Word 2010</product>
          <product>Microsoft Word 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2380"/>
        <description>Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:45.896-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.967-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:26.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="Check if the version of winword.exe is less than 12.0.6726.5000" test_ref="oval:org.mitre.oval:tst:141290"/>
        </criteria>
        <criteria operator="AND" comment="Word 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2010 is installed" definition_ref="oval:org.mitre.oval:def:7631"/>
          <criterion comment="Check if the version of winword.exe is less than 14.0.7153.5002" test_ref="oval:org.mitre.oval:tst:141421"/>
        </criteria>
        <criteria operator="AND" comment="Word 2013  and vulnerable file version">
          <extend_definition comment="Microsoft Word 2013 is installed" definition_ref="oval:org.mitre.oval:def:15560"/>
          <criterion comment="Check if the version of winword.exe is less than 15.0.4737.1003" test_ref="oval:org.mitre.oval:tst:141304"/>
        </criteria>
        <criteria operator="AND" comment="Word Viewer and vulnerable file version">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="Check if the version of wordview.exe is less than 11.0.8419" test_ref="oval:org.mitre.oval:tst:141357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29436" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of privilege vulnerability - CVE-2015-2363 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2363"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:54.125-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.626-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29431" version="3" class="vulnerability">
      <metadata>
        <title>Windows installer EoP vulnerability - CVE-2015-2371 (MS15-074)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2371"/>
        <description>The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a custom action script associated with a .msi package, aka "Windows Installer EoP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:27:30.824-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.162-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of msi.dll is less than 4.5.6002.19424" test_ref="oval:org.mitre.oval:tst:140643"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of msi.dll is greater than or equal to 4.5.6002.23000" test_ref="oval:org.mitre.oval:tst:140917"/>
              <criterion comment="Check if the version of msi.dll is less than 4.5.6002.23730" test_ref="oval:org.mitre.oval:tst:141315"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of msi.dll is less than 5.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141258"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of msi.dll is greater than or equal to 5.0.7601.23000" test_ref="oval:org.mitre.oval:tst:140322"/>
              <criterion comment="Check if the version of msi.dll is less than 5.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141164"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of msi.dll is less than 5.0.9600.17905" test_ref="oval:org.mitre.oval:tst:140784"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msi.dll is less than 4.5.6002.23731" test_ref="oval:org.mitre.oval:tst:141276"/>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of msi.dll is less than 5.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141175"/>
              <criterion comment="Check if the version of msi.dll is greater than or equal to 5.0.9200.21000" test_ref="oval:org.mitre.oval:tst:141015"/>
            </criteria>
            <criterion comment="Check if the version of msi.dll is less than 5.0.9200.17412" test_ref="oval:org.mitre.oval:tst:141240"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29422" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer information disclosure vulnerability - CVE-2015-2413 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2413" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2413" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:56.062-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.512-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29418" version="2" class="vulnerability">
      <metadata>
        <title>Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 (CVE-2005-2470)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Acrobat</product>
          <product>Adobe Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2470"/>
        <description>Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-30T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-07-31T12:47:22.692-04:00">DRAFT</status_change>
            <status_change date="2015-08-17T04:01:40.913-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check version of Acrobat">
          <extend_definition comment="Adobe Acrobat is installed" definition_ref="oval:org.mitre.oval:def:28344"/>
          <criteria operator="OR" comment="Adobe Acrobat version check">
            <criterion comment="Check if the version of Adobe Acrobat is less than 5.0.5" test_ref="oval:org.mitre.oval:tst:141184"/>
            <criterion comment="Check if the version of Adobe Acrobat is less than 6.0.3" test_ref="oval:org.mitre.oval:tst:141377"/>
            <criterion comment="Check if the version of Adobe Acrobat is less than 7.0.2" test_ref="oval:org.mitre.oval:tst:141106"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check version of Reader">
          <extend_definition comment="Adobe Reader is installed" definition_ref="oval:org.mitre.oval:def:27788"/>
          <criteria operator="OR" comment="Adobe Reader version check">
            <criterion comment="Check if the version of Adobe Reader 5.1" test_ref="oval:org.mitre.oval:tst:141435"/>
            <criterion comment="Check if the version of Adobe Reader is less than 6.0.3" test_ref="oval:org.mitre.oval:tst:141456"/>
            <criterion comment="Check if the version of Adobe Reader is less than 7.0.2" test_ref="oval:org.mitre.oval:tst:141004"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28344" version="3" class="inventory">
      <metadata>
        <title>Adobe Acrobat is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Acrobat</product>
        </affected>
        <reference ref_id="cpe:/a:adobe:acrobat" source="CPE"/>
        <description>Adobe Acrobat is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-21T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-11-26T15:40:03.682-05:00">DRAFT</status_change>
            <status_change date="2014-12-15T04:03:42.231-05:00">INTERIM</status_change>
            <status_change date="2015-01-05T04:00:33.652-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Adobe Acrobat is installed" test_ref="oval:org.mitre.oval:tst:135646"/>
        <criterion comment="^SOFTWARE\\Adobe\\Adobe Acrobat\\[\d\.]+\\Installer" test_ref="oval:org.mitre.oval:tst:135596"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27788" version="3" class="inventory">
      <metadata>
        <title>Adobe Reader is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Reader</product>
        </affected>
        <reference ref_id="cpe:/a:adobe:reader" source="CPE"/>
        <description>Adobe Reader is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-21T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-11-26T15:40:04.004-05:00">DRAFT</status_change>
            <status_change date="2014-12-15T04:02:57.440-05:00">INTERIM</status_change>
            <status_change date="2015-01-05T04:00:15.240-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Adobe Reader is installed" test_ref="oval:org.mitre.oval:tst:135600"/>
        <criterion comment="^SOFTWARE\\Adobe\\Adobe Reader\\[\d\.]+\\Installer" test_ref="oval:org.mitre.oval:tst:135562"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29414" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1738 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1738" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2388.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:08.650-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.296-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29400" version="2" class="vulnerability">
      <metadata>
        <title>Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers (CVE-2007-3457)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Adobe Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3457"/>
        <description>Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-30T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-07-31T12:47:22.038-04:00">DRAFT</status_change>
            <status_change date="2015-08-17T04:01:40.800-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Adobe Flash Player on Windows is less than or equal 8.0.34.0">
          <extend_definition comment="Adobe Flash Player is installed" definition_ref="oval:org.mitre.oval:def:6700"/>
          <criterion comment="Adobe Flash Player version is less than or equal to 8.0.34.0" test_ref="oval:org.mitre.oval:tst:141420"/>
        </criteria>
        <criteria operator="AND" comment="Flash.ocx section">
          <extend_definition comment="ActiveX Control is installed" definition_ref="oval:org.mitre.oval:def:26707"/>
          <criterion comment="Determine if the version of Flash.ocx is less than or equal 8.0.34.0" test_ref="oval:org.mitre.oval:tst:141197"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29395" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2389 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2389" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1733 and CVE-2015-2411.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:42.224-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:53.843-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29392" version="3" class="vulnerability">
      <metadata>
        <title>Remote Desktop Protocol (RDP) remote code execution vulnerability - CVE-2015-2373 (MS15-067)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2373"/>
        <description>The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a series of crafted packets, aka "Remote Desktop Protocol (RDP) Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T09:38:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T08:15:21.344-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:53.339-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:23.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.18892" test_ref="oval:org.mitre.oval:tst:140861"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.23095" test_ref="oval:org.mitre.oval:tst:140926"/>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:114959"/>
            </criteria>
            <criteria operator="AND" comment="rdpcorets.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21506" test_ref="oval:org.mitre.oval:tst:141412"/>
                  <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
                </criteria>
                <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17395" test_ref="oval:org.mitre.oval:tst:141388"/>
              </criteria>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17395" test_ref="oval:org.mitre.oval:tst:141388"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21506" test_ref="oval:org.mitre.oval:tst:141412"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Win 8 (32 / 64) and 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29360" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2422 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2422" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, and CVE-2015-2406.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:11.475-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:52.125-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:23.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29357" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2404 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2404" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:01.266-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:51.680-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:22.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29355" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-2421 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2421" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:05.529-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:50.170-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:22.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29332" version="3" class="vulnerability">
      <metadata>
        <title>ATMFD.DLL Memory corruption vulnerability - CVE-2015-2387 (MS15-077)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2387"/>
        <description>ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:32:13.105-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:49.766-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.242" test_ref="oval:org.mitre.oval:tst:140421"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.242" test_ref="oval:org.mitre.oval:tst:141178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29327" version="3" class="vulnerability">
      <metadata>
        <title>Windows RPC elevation of privilege vulnerability - CVE-2015-2370 (MS15-076)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2370"/>
        <description>The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prevent DCE/RPC connection reflection, which allows local users to gain privileges via a crafted application, aka "Windows RPC Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:30:38.407-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:49.319-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 5.2.3790.5669" test_ref="oval:org.mitre.oval:tst:141239"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.0.6002.19431" test_ref="oval:org.mitre.oval:tst:141076"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135821"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.0.6002.23737" test_ref="oval:org.mitre.oval:tst:140349"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.1.7601.18909" test_ref="oval:org.mitre.oval:tst:140560"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135603"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.1.7601.23112" test_ref="oval:org.mitre.oval:tst:141041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/ Server 2012 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8/ Server 2012 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.17420" test_ref="oval:org.mitre.oval:tst:140691"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135794"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.21529" test_ref="oval:org.mitre.oval:tst:141299"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 6.3.9600.17918" test_ref="oval:org.mitre.oval:tst:140736"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29324" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2397 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2397" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:24.103-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.951-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29316" version="3" class="vulnerability">
      <metadata>
        <title>Jscript9 Memory corruption vulnerability - CVE-2015-2419 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2419" source="CVE"/>
        <description>JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:21.268-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.651-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:20.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29315" version="3" class="vulnerability">
      <metadata>
        <title>SQL Server remote code execution vulnerability - CVE-2015-1763 (MS15-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft SQL Server 2008</product>
          <product>Microsoft SQL Server 2008 R2</product>
          <product>Microsoft SQL Server 2012</product>
          <product>Microsoft SQL Server 2014</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1763"/>
        <description>Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attempts to execute virtual functions, which allows remote authenticated users to execute arbitrary code via a crafted query, aka "SQL Server Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:09:52.799-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.155-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:20.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft SQL Server 2008 and vulnerable file version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2008 is installed" definition_ref="oval:org.mitre.oval:def:12454"/>
            <extend_definition comment="Microsoft SQL Server 2008 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15497"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.5538.0" test_ref="oval:org.mitre.oval:tst:140857"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.0.5750.0" test_ref="oval:org.mitre.oval:tst:121683"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.5890.0" test_ref="oval:org.mitre.oval:tst:140253"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2008 Service Pack 4 is installed" definition_ref="oval:org.mitre.oval:def:28999"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.6535.0" test_ref="oval:org.mitre.oval:tst:141246"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.0.6500.0" test_ref="oval:org.mitre.oval:tst:141186"/>
            </criteria>
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.0.6241.0" test_ref="oval:org.mitre.oval:tst:141140"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12596"/>
            <extend_definition comment="Microsoft SQL Server 2008 R2 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15803"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.4042.0" test_ref="oval:org.mitre.oval:tst:140756"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.50.4251" test_ref="oval:org.mitre.oval:tst:122178"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.4339.0" test_ref="oval:org.mitre.oval:tst:141132"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2008 R2 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2008 R2 SP3 is installed" definition_ref="oval:org.mitre.oval:def:28713"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.6220.0" test_ref="oval:org.mitre.oval:tst:140888"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 10.50.6529.0" test_ref="oval:org.mitre.oval:tst:140717"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 10.50.6500.0" test_ref="oval:org.mitre.oval:tst:140270"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2012 vulnerable version">
          <criteria operator="OR" comment="either products">
            <extend_definition comment="Microsoft SQL Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:15044"/>
            <extend_definition comment="Microsoft SQL Server 2012 SP1 is installed" definition_ref="oval:org.mitre.oval:def:21029"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.3156.0" test_ref="oval:org.mitre.oval:tst:141009"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 11.0.3300" test_ref="oval:org.mitre.oval:tst:122379"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.3513.0" test_ref="oval:org.mitre.oval:tst:141172"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2012 vulnerable version">
          <extend_definition comment="Microsoft SQL Server 2012 SP2 is installed" definition_ref="oval:org.mitre.oval:def:29429"/>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.5343.0" test_ref="oval:org.mitre.oval:tst:141193"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 11.0.5613.0" test_ref="oval:org.mitre.oval:tst:141079"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 11.0.5600.0" test_ref="oval:org.mitre.oval:tst:141019"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft SQL Server 2014 and vulnerable file version">
          <extend_definition comment="Microsoft SQL Server 2014 is installed" definition_ref="oval:org.mitre.oval:def:26140"/>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 12.0.2269.0" test_ref="oval:org.mitre.oval:tst:141088"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is greater than or equal to 12.0.2300" test_ref="oval:org.mitre.oval:tst:122271"/>
              <criterion comment="Check if the version of Microsoft.sqlserver.chainer.infrastructure.dll is less than 12.0.2548.0" test_ref="oval:org.mitre.oval:tst:141078"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29429" version="3" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2012 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SQL Server 2012</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2012:sp2"/>
        <description>Microsoft SQL Server 2012 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:09:50.234-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.072-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SQL Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:15044"/>
        <criterion comment="Check if SQL Server 2012 SP2 is installed" test_ref="oval:org.mitre.oval:tst:140967"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28999" version="3" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2008 Service Pack 4 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SQL Server 2008</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2008:sp4"/>
        <description>Microsoft SQL Server 2008 Service Pack 4 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:09:48.997-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:41.953-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SQL Server 2008 is installed" definition_ref="oval:org.mitre.oval:def:12454"/>
        <criterion comment="Check if SQL Server 2008 SP4 is installed" test_ref="oval:org.mitre.oval:tst:141117"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28713" version="3" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2008 R2 SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SQL Server 2008 R2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2008_r2:sp3"/>
        <description>Microsoft SQL Server 2008 R2 SP3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:09:49.718-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:35.989-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:07.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SQL Server 2008 R2 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15803"/>
        <criterion comment="Check if SQL Server 2008 R2 SP3 is installed" test_ref="oval:org.mitre.oval:tst:140257"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21029" version="13" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2012 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SQL Server 2012</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2012:sp1"/>
        <description>Microsoft SQL Server 2012 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-20T13:00:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-12-20T10:59:24.516-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:47.096-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:55.382-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26798 - &quot;MSSQL&quot; added to object regex to narrow search" date="2014-01-31T16:01:00.799-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-31T16:02:49.400-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.141-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26674 - Added criteria for 64 bit" date="2014-08-15T08:00:00.371-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-15T10:20:20.871-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:32.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26798 - Fixed/New Inventory Definitions, and fixed Vulnerability Definitions for Microsoft SQL Server 2012 and 2014." date="2014-10-10T18:35:00.565-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-10-10T19:58:53.430-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:12.609-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26674 - Modified tests which check SQL Server 2005 Service Packs. The specific version of SQL Server was checked instead of diapason. Now new states were added which mark high limit of SP and operation=&quot;greater than or equal&quot; was add to the old states" date="2014-10-29T12:41:00.258-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-10-29T12:42:38.031-04:00">INTERIM</status_change>
            <status_change date="2014-11-17T04:00:22.809-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89900 - MS bulletins for the month of July 2015." date="2015-07-23T11:07:00.045-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-07-23T11:09:56.252-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:23.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft SQL Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:15044"/>
        <criterion comment="Check if SQL Server 2012 SP1 is installed" test_ref="oval:org.mitre.oval:tst:89900"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29296" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2425 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2425" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2425" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:28.790-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.724-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29295" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1729 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1729" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:17.942-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.501-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29292" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2408 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2408" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:02.935-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.245-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.108-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29284" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability - CVE-2015-2379 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Word Viewer</product>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Word 2010</product>
          <product>Microsoft Word 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2379"/>
        <description>Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:46.733-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.117-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:18.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="Check if the version of winword.exe is less than 12.0.6726.5000" test_ref="oval:org.mitre.oval:tst:141290"/>
        </criteria>
        <criteria operator="AND" comment="Word 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2010 is installed" definition_ref="oval:org.mitre.oval:def:7631"/>
          <criterion comment="Check if the version of winword.exe is less than 14.0.7153.5002" test_ref="oval:org.mitre.oval:tst:141421"/>
        </criteria>
        <criteria operator="AND" comment="Word 2013  and vulnerable file version">
          <extend_definition comment="Microsoft Word 2013 is installed" definition_ref="oval:org.mitre.oval:def:15560"/>
          <criterion comment="Check if the version of winword.exe is less than 15.0.4737.1003" test_ref="oval:org.mitre.oval:tst:141304"/>
        </criteria>
        <criteria operator="AND" comment="Word Viewer and vulnerable file version">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="Check if the version of wordview.exe is less than 11.0.8419" test_ref="oval:org.mitre.oval:tst:141357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29280" version="3" class="vulnerability">
      <metadata>
        <title>Windows DLL remote code execution vulnerability - CVE-2015-2368 (MS15-069)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2368"/>
        <description>Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Windows DLL Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T10:06:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:20:31.123-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:29280 - Removed unneeded file checks" date="2015-07-27T14:44:00.654-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T04:01:30.053-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criterion comment="Check if the version of wksprt.exe is less than 6.3.9600.17901" test_ref="oval:org.mitre.oval:tst:141280"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 (x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <criterion comment="Check if the version of atlthunk.dll is less than 6.3.9600.17415" test_ref="oval:org.mitre.oval:tst:141198"/>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/2k12 R2(64 bit) and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2 (x64)">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version Atlthunk.dll is less than 6.3.9600.17670 (SysWow64)" test_ref="oval:org.mitre.oval:tst:141270"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29278" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2385 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2385" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:38.192-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.768-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:18.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29247" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2391 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-2391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2391" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:32.143-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.501-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:17.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29245" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability - CVE-2015-2376 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Excel 2010</product>
          <product>Microsoft Excel 2013</product>
          <product>Microsoft Excel Viewer 2007</product>
          <product>Microsoft Office Compatibility Pack</product>
          <product>Microsoft SharePoint Server 2007</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2376"/>
        <description>Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Office for Mac 2011, Excel Viewer 2007 SP3, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:51.642-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.258-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:17.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Excel 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Check if the version of excel.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:140929"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2010 is installed" definition_ref="oval:org.mitre.oval:def:12658"/>
          <criterion comment="Check if the version of excel.exe is less than 14.0.7153.5000" test_ref="oval:org.mitre.oval:tst:141097"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2013 is installed" definition_ref="oval:org.mitre.oval:def:15563"/>
          <criterion comment="Check if the version of excel.exe is less than 15.0.4737.1000" test_ref="oval:org.mitre.oval:tst:141327"/>
        </criteria>
        <criteria operator="AND" comment="Excel Viewer and vulnerable file version">
          <extend_definition comment="Microsoft Excel Viewer 2007 is installed" definition_ref="oval:org.mitre.oval:def:6006"/>
          <criterion comment="Check if the version of xlview.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:141331"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007 and vulnerable version">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="Check if the version of excelcnv.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:140850"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of xlsrv.dll is less than 14.0.7153.5000" test_ref="oval:org.mitre.oval:tst:141344"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4737.1000" test_ref="oval:org.mitre.oval:tst:140889"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="Check if the version of xlsrv.dll is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:141318"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29219" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2411 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2411" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1733 and CVE-2015-2389.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:07.261-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.027-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:17.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29198" version="3" class="vulnerability">
      <metadata>
        <title>OLE Elevation of privilege vulnerability - CVE-2015-2417 (MS15-075)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2417"/>
        <description>OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2416.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:29:09.429-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.570-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 5.2.3790.5663" test_ref="oval:org.mitre.oval:tst:140974"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.19435" test_ref="oval:org.mitre.oval:tst:140324"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141237"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.23743" test_ref="oval:org.mitre.oval:tst:140765"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.18896" test_ref="oval:org.mitre.oval:tst:141296"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141207"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.23099" test_ref="oval:org.mitre.oval:tst:140818"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.21524" test_ref="oval:org.mitre.oval:tst:141136"/>
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:140969"/>
            </criteria>
            <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.17414" test_ref="oval:org.mitre.oval:tst:141309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 6.3.9600.17905" test_ref="oval:org.mitre.oval:tst:140986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29164" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2383 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2383" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2384 and CVE-2015-2425.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:51.318-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.334-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29159" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2412 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2412" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:15.003-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.142-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29156" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2365 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2365"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:49.098-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:44.843-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:15.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29149" version="3" class="vulnerability">
      <metadata>
        <title>DLL planting remote code execution vulnerability - CVE-2015-2369 (MS15-069)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2369" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2369"/>
        <description>Untrusted search path vulnerability in Windows Media Device Manager in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rtf file, aka "DLL Planting Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T10:06:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:20:29.893-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:29149 - Removed unneeded file checks" date="2015-07-27T14:42:00.063-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T04:01:02.218-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of cewmdm.dll is less than 12.0.7601.18872" test_ref="oval:org.mitre.oval:tst:141176"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of cewmdm.dll is greater than or equal to 12.0.7601.23000" test_ref="oval:org.mitre.oval:tst:141218"/>
              <criterion comment="Check if the version of cewmdm.dll is less than 12.0.7601.23075" test_ref="oval:org.mitre.oval:tst:140851"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2003(x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of cewmdm.dll is less than 10.0.3790.4011" test_ref="oval:org.mitre.oval:tst:140828"/>
        </criteria>
        <criteria operator="AND" comment="2k3(x64) and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <criterion comment="Check if the version of wcewmdm.dll is less than 10.0.3790.4011" test_ref="oval:org.mitre.oval:tst:141308"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of cewmdm.dll is less than 11.0.6002.19403" test_ref="oval:org.mitre.oval:tst:141071"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of cewmdm.dll is greater than or equal to 11.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141312"/>
              <criterion comment="Check if the version of cewmdm.dll is less than 11.0.6002.23710" test_ref="oval:org.mitre.oval:tst:141109"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29147" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1743 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1743" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:19.881-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.948-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:12.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29145" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Null pointer dereference vulnerability - CVE-2015-1721 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1721"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer Dereference Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:15.663-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.736-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:12.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29142" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1739 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1739" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:42.416-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.092-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:11.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29139" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability - CVE-2015-2375 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Excel 2010</product>
          <product>Microsoft Excel 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2375"/>
        <description>Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spreadsheet, aka "Microsoft Excel ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:44.782-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:44.226-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:15.170-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Excel 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2010 is installed" definition_ref="oval:org.mitre.oval:def:12658"/>
          <criterion comment="Check if the version of excel.exe is less than 14.0.7153.5000" test_ref="oval:org.mitre.oval:tst:141097"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2013 is installed" definition_ref="oval:org.mitre.oval:def:15563"/>
          <criterion comment="Check if the version of excel.exe is less than 15.0.4737.1000" test_ref="oval:org.mitre.oval:tst:141327"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of xlsrv.dll is less than 14.0.7153.5000" test_ref="oval:org.mitre.oval:tst:141344"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4737.1000" test_ref="oval:org.mitre.oval:tst:140889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29128" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2366 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2366"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:55.121-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.840-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29124" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Object use after free vulnerability - CVE-2015-1724 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1724"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Object Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:31.348-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.463-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:08.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29123" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1740 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1740" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1744, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:36.047-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.166-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:08.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29119" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1742 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1742" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1742" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1747, CVE-2015-1750, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:08.967-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.017-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:07.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29118" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel use after free vulnerability – CVE-2015-1720 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1720"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:13.516-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:43.770-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:07.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29113" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1735 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1735" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1735" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1740, CVE-2015-1744, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:32.864-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:43.444-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:06.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29093" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel information disclosure vulnerability – CVE-2015-1719 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1719"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to obtain sensitive information from kernel memory via a crafted application, aka "Microsoft Windows Kernel Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:33.625-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:42.325-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:03.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29087" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2410 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2410" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:46.838-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.376-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.068-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29081" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1687 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1687" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:05.893-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:41.702-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:01.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29076" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1766 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1766" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:13.617-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:40.866-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:00.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29075" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2015-2398 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2398" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:44.325-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.058-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:13.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29072" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft common control use after free vulnerability - CVE-2015-1756 (MS15-060)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1756" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1756"/>
        <description>Use-after-free vulnerability in Microsoft Common Controls in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted web site that is accessed with the F12 Developer Tools feature of Internet Explorer, aka "Microsoft Common Control Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T08:09:33">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:22:04.051-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:39.471-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:59.876-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2008 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of comctl32.dll is less than 6.10.6002.19373" test_ref="oval:org.mitre.oval:tst:138710"/>
            <criterion comment="Check if the version of comctl32.dll is greater than or equal to 6.10.6002.23000 and less than 6.10.6002.23681" test_ref="oval:org.mitre.oval:tst:139054"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of comctl32.dll is less than 6.10.7601.18837" test_ref="oval:org.mitre.oval:tst:138949"/>
            <criterion comment="Check if the version of comctl32.dll is greater than or equal to 6.10.7601.23000 and less than 6.10.7601.23039" test_ref="oval:org.mitre.oval:tst:138916"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of comctl32.dll is less than 6.10.9200.17359" test_ref="oval:org.mitre.oval:tst:138946"/>
            <criterion comment="Check if the version of comctl32.dll is greater than or equal to 6.10.9200.21000 and less than 6.10.9200.21472" test_ref="oval:org.mitre.oval:tst:139068"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1 or 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of comctl32.dll is less than 6.10.9600.17810" test_ref="oval:org.mitre.oval:tst:138835"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29067" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Station use after free vulnerability - CVE-2015-1723 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1723" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1723"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Station Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:17.588-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:39.183-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:57.483-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29061" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1753 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1753" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1747, and CVE-2015-1750.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:23.236-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:39.061-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:57.103-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29060" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1751 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1751" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:03.315-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.875-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29057" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1747 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1747" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1747" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1732, CVE-2015-1742, CVE-2015-1750, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:27.051-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.734-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29050" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Pool buffer overflow vulnerability - CVE-2015-1727 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1727"/>
        <description>Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Pool Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:26.307-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.464-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.042-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29033" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1732 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1732" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1742, CVE-2015-1747, CVE-2015-1750, and CVE-2015-1753.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:20.730-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.232-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:53.961-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29018" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Management Console file format denial of service vulnerability - CVE-2015-1681 (MS15-054)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1681"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service via a crafted .msc file, aka "Microsoft Management Console File Format Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T15:47:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:39:20.408-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:33.029-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:37.783-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2008 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of comctl32.dll is less than 6.10.6002.19355" test_ref="oval:org.mitre.oval:tst:138816"/>
            <criterion comment="Check if the version of comctl32.dll is greater than or equal to 6.10.6002.23000 and less than 6.10.6002.23663" test_ref="oval:org.mitre.oval:tst:138678"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of comctl32.dll is less than 6.10.7601.18807" test_ref="oval:org.mitre.oval:tst:138860"/>
            <criterion comment="Check if the version of comctl32.dll is greater than or equal to 6.10.7601.23000 and less than 6.10.7601.23011" test_ref="oval:org.mitre.oval:tst:138820"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of comctl32.dll is less than 6.10.9200.17321" test_ref="oval:org.mitre.oval:tst:137909"/>
            <criterion comment="Check if the version of comctl32.dll is greater than or equal to 6.10.9200.21000 and less than 6.10.9200.21435" test_ref="oval:org.mitre.oval:tst:137938"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1 or 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of comctl32.dll is less than 6.10.9600.17784" test_ref="oval:org.mitre.oval:tst:138363"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29016" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-1685 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1685" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1685" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:12.160-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.856-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:37.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29015" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1767 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1767" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2401 and CVE-2015-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:33.802-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:42.386-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29010" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2403 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-2403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2403" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:25.540-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:42.119-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29009" version="4" class="vulnerability">
      <metadata>
        <title>MSXML3 same origin policy SFB vulnerability - CVE-2015-1646 (MS15-039)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft XML Core Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1646" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1646"/>
        <description>Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-24T20:56:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-12T14:22:30.361-04:00">DRAFT</status_change>
            <status_change date="2015-06-01T04:00:23.144-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:45.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 vulnerable version">
          <criteria operator="OR" comment="Server (2003 - x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="Check if the version of msxml3.dll is less than 8.100.1057.0" test_ref="oval:org.mitre.oval:tst:138415"/>
        </criteria>
        <criteria operator="AND" comment="Vista/ 2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista /2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="Check if the version of msxml3.dll is less than 8.100.5010.0" test_ref="oval:org.mitre.oval:tst:138091"/>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msxml3.dll is less than 8.110.7601.18782" test_ref="oval:org.mitre.oval:tst:138590"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
              <criterion comment="Check if the version of msxml3.dll is less than 8.110.7601.22986" test_ref="oval:org.mitre.oval:tst:138589"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29005" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1748 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1748" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1743.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:16.086-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:37.151-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:49.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29001" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1676 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1676"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1677, CVE-2015-1678, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:23.410-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.607-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29000" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1658 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1658" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1706, CVE-2015-1711, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:28.786-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.446-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28994" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2360 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2360"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:21.750-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:36.298-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:49.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28993" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1717 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1717" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1711, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:15.134-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.271-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28990" version="3" class="vulnerability">
      <metadata>
        <title>OLE Elevation of privilege vulnerability - CVE-2015-2416 (MS15-075)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2416"/>
        <description>OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:29:07.182-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:41.628-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 5.2.3790.5663" test_ref="oval:org.mitre.oval:tst:140974"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.19435" test_ref="oval:org.mitre.oval:tst:140324"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141237"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.23743" test_ref="oval:org.mitre.oval:tst:140765"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.18896" test_ref="oval:org.mitre.oval:tst:141296"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141207"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.23099" test_ref="oval:org.mitre.oval:tst:140818"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.21524" test_ref="oval:org.mitre.oval:tst:141136"/>
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:140969"/>
            </criteria>
            <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.17414" test_ref="oval:org.mitre.oval:tst:141309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 6.3.9600.17905" test_ref="oval:org.mitre.oval:tst:140986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28985" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Silverlight out of browser application vulnerability - CVE-2015-1715 (MS15-049)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Silverlight 5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1715"/>
        <description>Microsoft Silverlight 5 before 5.1.40416.00 allows remote attackers to bypass intended integrity-level restrictions via a crafted Silverlight application, aka "Microsoft Silverlight Out of Browser Application Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T16:48:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:21.264-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.183-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Silverlight 5 is installed" definition_ref="oval:org.mitre.oval:def:15148"/>
        <criterion comment="Check if the version of silverlight is less than 5.1.40416.0" test_ref="oval:org.mitre.oval:tst:138651"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28984" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1709 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1709" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1709" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:22.678-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.731-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28951" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1705 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1705" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1705" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1689.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:24.391-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.424-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28950" version="4" class="vulnerability">
      <metadata>
        <title>Windows forms elevation of privilege vulnerability - CVE-2015-1673 (MS15-048)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1673"/>
        <description>The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:34:59.080-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.089-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:34.795-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28950 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:16.687-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2512" test_ref="oval:org.mitre.oval:tst:138654"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8655" test_ref="oval:org.mitre.oval:tst:138616"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.3667" test_ref="oval:org.mitre.oval:tst:138084"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.4257" test_ref="oval:org.mitre.oval:tst:138542"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.6427" test_ref="oval:org.mitre.oval:tst:138639"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.5491" test_ref="oval:org.mitre.oval:tst:137946"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.2057" test_ref="oval:org.mitre.oval:tst:138799"/>
              <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80817"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.1032" test_ref="oval:org.mitre.oval:tst:138641"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36287" test_ref="oval:org.mitre.oval:tst:138838"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34251" test_ref="oval:org.mitre.oval:tst:138683"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36286" test_ref="oval:org.mitre.oval:tst:138687"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34250" test_ref="oval:org.mitre.oval:tst:138511"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36286" test_ref="oval:org.mitre.oval:tst:138687"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34250" test_ref="oval:org.mitre.oval:tst:138511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28948" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1755 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1755" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1737.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:28.677-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:34.461-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:45.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28938" version="3" class="vulnerability">
      <metadata>
        <title>VBScript Memory corruption vulnerability - CVE-2015-2372 (MS15-065 and MS15-066)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft VBScript 5.6</product>
          <product>Microsoft VBScript 5.7</product>
          <product>Microsoft VBScript 5.8</product>
        </affected>
        <reference ref_id="CVE-2015-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2372" source="CVE"/>
        <description>vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:31.155-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:40.445-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:10.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <criterion comment="vbscript.dll 5.6 or later is installed" test_ref="oval:org.mitre.oval:tst:100534"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of VBScript.dll is less than 5.6.0.8856" test_ref="oval:org.mitre.oval:tst:141230"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <criterion comment="Vbscript.dll 5.7 or later is installed" test_ref="oval:org.mitre.oval:tst:11558"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23712" test_ref="oval:org.mitre.oval:tst:140314"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.19405" test_ref="oval:org.mitre.oval:tst:141294"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23712" test_ref="oval:org.mitre.oval:tst:140314"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2 + IE 8 vulnerable version">
              <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="2k3 and vulnerable version">
                  <criteria operator="OR" comment="2K3">
                    <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                    <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23707" test_ref="oval:org.mitre.oval:tst:140824"/>
                </criteria>
                <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
                  <criteria operator="OR" comment="Vista / 2K8">
                    <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                    <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19652" test_ref="oval:org.mitre.oval:tst:141188"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23707" test_ref="oval:org.mitre.oval:tst:140824"/>
                      <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  </criteria>
                  <criteria operator="OR" comment="vulnerable file version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18896" test_ref="oval:org.mitre.oval:tst:141265"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.23099" test_ref="oval:org.mitre.oval:tst:140984"/>
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.7601.23000" test_ref="oval:org.mitre.oval:tst:138193"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 9 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17174" test_ref="oval:org.mitre.oval:tst:140884"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20785" test_ref="oval:org.mitre.oval:tst:141278"/>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <criterion comment="Check if Microsoft Internet Explorer 10 is installed" test_ref="oval:org.mitre.oval:tst:80429"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17410" test_ref="oval:org.mitre.oval:tst:140995"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21521" test_ref="oval:org.mitre.oval:tst:141291"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/2k8 R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/2k8 R2/Win8.1/2k12 R2 and vulnerable file version">
                <criteria operator="AND" comment="Win7 x86 and vulnerable version">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17909" test_ref="oval:org.mitre.oval:tst:141182"/>
                </criteria>
                <criteria operator="AND" comment="Win7 x64 / Server 2008 R2 and vulnerable version">
                  <criteria operator="OR" comment="Win 7 / R2">
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17910" test_ref="oval:org.mitre.oval:tst:141085"/>
                </criteria>
                <criteria operator="AND" comment="Win 8.1  / Server 2012 R2 and vulnerable version">
                  <criteria operator="OR" comment="Win 7 / R2">
                    <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                    <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                    <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17905" test_ref="oval:org.mitre.oval:tst:140873"/>
                </criteria>
              </criteria>
              <criterion comment="Check if Microsoft Internet Explorer 11 is installed" test_ref="oval:org.mitre.oval:tst:87142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28936" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1699 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1699"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, and CVE-2015-1698.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:49.383-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:30.836-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:34.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28932" version="3" class="vulnerability">
      <metadata>
        <title>Service control manager elevation of privilege vulnerability - CVE-2015-1702 (MS15-050)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1702"/>
        <description>The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Service Control Manager Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:39:47">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:37:09.571-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:30.416-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of services.exe is less than 6.0.6002.19369" test_ref="oval:org.mitre.oval:tst:138682"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138469"/>
              <criterion comment="Check if the version of services.exe is less than 6.0.6002.23677" test_ref="oval:org.mitre.oval:tst:138468"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of services.exe is less than 6.1.7601.18829" test_ref="oval:org.mitre.oval:tst:138200"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138798"/>
              <criterion comment="Check if the version of services.exe is less than 6.1.7601.23033" test_ref="oval:org.mitre.oval:tst:138581"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of services.exe is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138750"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138360"/>
              <criterion comment="Check if the version of services.exe is less than 6.2.9200.21456" test_ref="oval:org.mitre.oval:tst:138573"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of services.exe is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:137869"/>
        </criteria>
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28924" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint page content vulnerabilities – CVE-2015-1700 (MS15-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Server 2007</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1700"/>
        <description>Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T20:21:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:09:54.328-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-06-15T04:00:30.063-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint 2007 and vulnerable file versions">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="Check if the version of Microsoft.SharePoint.Portal.dll is less than 12.0.6721.5000" test_ref="oval:org.mitre.oval:tst:137831"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of Microsoft.office.policy.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138630"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2010 / 2010 SP1">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138555"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4719.1002" test_ref="oval:org.mitre.oval:tst:138608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28917" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1718 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1718" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1711, and CVE-2015-1717.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:59.485-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.917-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:32.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28910" version="4" class="vulnerability">
      <metadata>
        <title>Windows Media Player RCE via DataObject vulnerability - CVE-2015-1728 (MS15-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1728"/>
        <description>Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows Media Player RCE via DataObject Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T13:23:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:17:11.575-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20961 - MS bulletins for the month of June 2015" date="2015-06-18T10:14:00.489-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-06T04:00:32.407-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:42.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Media Player 9">
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.4513" test_ref="oval:org.mitre.oval:tst:138941"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on windows server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4011" test_ref="oval:org.mitre.oval:tst:138849"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista /Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6002.19378" test_ref="oval:org.mitre.oval:tst:138461"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Wmp.dll is greater than or equal 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21257"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6002.23684" test_ref="oval:org.mitre.oval:tst:138068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 12 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Windows Media Player v12 is installed." definition_ref="oval:org.mitre.oval:def:7384"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Wmp.dll is less than 12.0.7601.18840" test_ref="oval:org.mitre.oval:tst:138814"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmp.dll is greater than or equal 12.0.7601.22000" test_ref="oval:org.mitre.oval:tst:138964"/>
              <criterion comment="The version of Wmp.dll is less than 12.0.7601.23041" test_ref="oval:org.mitre.oval:tst:138905"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows Server 2003 (x64-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wwmp.dll is less than 10.0.0.4011" test_ref="oval:org.mitre.oval:tst:20961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2172" version="9" class="inventory">
      <metadata>
        <title>Windows Media Player v10 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player 10</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:10"/>
        <description>Windows Media Player v10 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.378-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.729-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:32.988-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:18.161-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:09.298-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - inventory for Windows Media Player 10" date="2013-09-13T13:48:00.518-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:49:22.528-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:18.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.003-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 10.0.0.0" test_ref="oval:org.mitre.oval:tst:86658"/>
        <criterion comment="Check if Windows Media Player version is less than 11.0.0.0" test_ref="oval:org.mitre.oval:tst:86603"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2147" version="11" class="inventory">
      <metadata>
        <title>Windows Media Player v9 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:9"/>
        <description>Windows Media Player v9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.096-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.363-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:37.426-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.606-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:18.431-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:08.945-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - inventory for Windows Media Player 9" date="2013-09-13T13:46:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:48:00.391-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:18.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86573 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:19.904-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:10.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:27.374-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 9.0.0.0" test_ref="oval:org.mitre.oval:tst:86573"/>
        <criterion comment="Check if Windows Media Player version is less than 10.0.0.0" test_ref="oval:org.mitre.oval:tst:86682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28895" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1668 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1668" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:04.735-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:24.960-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28889" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1736 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1736" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1737, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:29.962-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:32.196-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:39.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28883" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1701 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1701" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1701"/>
        <description>Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:28.748-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.588-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:32.020-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28876" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1677 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1677"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1678, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:20.752-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.368-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:31.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28867" version="6" class="vulnerability">
      <metadata>
        <title>VBScript memory corruption vulnerability - CVE-2015-1684 (MS15-043 and MS15-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VBScript 5.6</product>
          <product>VBScript 5.7</product>
          <product>VBScript 5.8</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1684" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1684" source="CVE"/>
        <description>VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 through 11 and other products, allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T17:44:26.144+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:17.374-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.039-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:31.118-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28867 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:41:00.692-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:45:51.069-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:39.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <extend_definition comment="VBScript 5.6 is installed" definition_ref="oval:org.mitre.oval:def:28988"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of VBScript.dll is less than 5.6.0.8855" test_ref="oval:org.mitre.oval:tst:138604"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23659" test_ref="oval:org.mitre.oval:tst:138320"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.19351" test_ref="oval:org.mitre.oval:tst:138602"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23659" test_ref="oval:org.mitre.oval:tst:138320"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2 + IE 8 vulnerable version">
              <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="2k3 and vulnerable version">
                  <criteria operator="OR" comment="2K3">
                    <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                    <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23671" test_ref="oval:org.mitre.oval:tst:138609"/>
                </criteria>
                <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
                  <criteria operator="OR" comment="Vista / 2K8">
                    <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                    <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19612" test_ref="oval:org.mitre.oval:tst:138153"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23671" test_ref="oval:org.mitre.oval:tst:138609"/>
                      <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  </criteria>
                  <criteria operator="OR" comment="vulnerable file version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18806" test_ref="oval:org.mitre.oval:tst:137926"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.23010" test_ref="oval:org.mitre.oval:tst:138242"/>
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.7601.23000" test_ref="oval:org.mitre.oval:tst:138193"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
              <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 9 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17141" test_ref="oval:org.mitre.oval:tst:138375"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20751" test_ref="oval:org.mitre.oval:tst:138459"/>
                </criteria>
              </criteria>
              <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17296" test_ref="oval:org.mitre.oval:tst:138269"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21413" test_ref="oval:org.mitre.oval:tst:138512"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17728" test_ref="oval:org.mitre.oval:tst:138586"/>
              <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28865" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1660 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1660" source="CVE"/>
        <description>Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:20.026-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:24.159-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.437-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criteria operator="OR" comment="vista/2k8/win7/R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28861" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1666 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1666" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1652.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:18.735-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:23.867-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28851" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft word local zone remote code execution vulnerability – CVE-2015-0097 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Excel 2010</product>
          <product>Microsoft PowerPoint 2007</product>
          <product>Microsoft PowerPoint 2010</product>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Word 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0097"/>
        <description>Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T10:00:05.434-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:17.205-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:27.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Excel 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Check if the version of excel.exe is less than 12.0.6718.5000" test_ref="oval:org.mitre.oval:tst:138267"/>
        </criteria>
        <criteria operator="AND" comment="Powerpoint 2007 and vulnerable file version">
          <extend_definition comment="Microsoft PowerPoint 2007 is installed" definition_ref="oval:org.mitre.oval:def:5937"/>
          <criterion comment="Check if the version of ppcore.dll is less than 12.0.6718.5000" test_ref="oval:org.mitre.oval:tst:137963"/>
        </criteria>
        <criteria operator="AND" comment="Word 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="Check if the version of winword.exe is less than 12.0.6718.5000" test_ref="oval:org.mitre.oval:tst:138427"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2010 is installed" definition_ref="oval:org.mitre.oval:def:12658"/>
          <criterion comment="Check if the version of excel.exe is less than 14.0.7145.5001" test_ref="oval:org.mitre.oval:tst:138349"/>
        </criteria>
        <criteria operator="AND" comment="Powerpoint 2010 and vulnerable file version">
          <extend_definition comment="Microsoft PowerPoint 2010 is installed" definition_ref="oval:org.mitre.oval:def:12376"/>
          <criterion comment="Check if the version of ppcore.dll is less than 14.0.7145.5001" test_ref="oval:org.mitre.oval:tst:138204"/>
        </criteria>
        <criteria operator="AND" comment="Word 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2010 is installed" definition_ref="oval:org.mitre.oval:def:7631"/>
          <criterion comment="Check if the version of winword.exe is less than 14.0.7145.5001" test_ref="oval:org.mitre.oval:tst:138219"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28848" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1744 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1744" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:25.941-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:30.250-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:37.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28847" version="3" class="vulnerability">
      <metadata>
        <title>Remote desktop protocol (RDP) denial of service vulnerability - CVE-2015-0079 (MS15-030)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0079"/>
        <description>The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to cause a denial of service (memory consumption and RDP outage) by establishing many RDP sessions that do not properly free allocated memory, aka "Remote Desktop Protocol (RDP) Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:35:32.118-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.961-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:27.037-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.18740" test_ref="oval:org.mitre.oval:tst:138435"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.22947" test_ref="oval:org.mitre.oval:tst:138342"/>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:114959"/>
            </criteria>
            <criteria operator="AND" comment="rdpcorets.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21172" test_ref="oval:org.mitre.oval:tst:138455"/>
                  <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
                </criteria>
                <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17053" test_ref="oval:org.mitre.oval:tst:138420"/>
              </criteria>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138347"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:138201"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Rdpudd.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:138456"/>
              <criterion comment="Check if the version of Rdpudd.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138064"/>
            </criteria>
            <criterion comment="Check if the version of Rdpudd.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:137632"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of rdpcorets.dll is less than 6.3.9600.17667" test_ref="oval:org.mitre.oval:tst:138398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28844" version="3" class="vulnerability">
      <metadata>
        <title>Impersonation level check elevation of privilege vulnerability - CVE-2015-0075 (MS15-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0075"/>
        <description>The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Impersonation Level Check Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:18:59.294-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.674-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if version of Fltmgr.sys is less than 5.2.3790.5107" test_ref="oval:org.mitre.oval:tst:138447"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138397"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:137988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22943" test_ref="oval:org.mitre.oval:tst:138117"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18738" test_ref="oval:org.mitre.oval:tst:138289"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28843" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1624 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1624" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:27.309-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.411-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28840" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1712 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-1712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1712" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1691.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:05.231-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.634-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.944-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28836" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0100 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-0100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0100" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:37.833-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.222-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28834" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2406 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2406" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:27.990-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:39.346-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:10.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28831" version="3" class="vulnerability">
      <metadata>
        <title>NtCreateTransactionManager type confusion vulnerability - CVE-2015-1643 (MS15-038)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1643"/>
        <description>Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "NtCreateTransactionManager Type Confusion Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T12:36:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:20:34.323-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:22.974-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:21.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.0.6002.19331" test_ref="oval:org.mitre.oval:tst:138203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138245"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.0.6002.23639" test_ref="oval:org.mitre.oval:tst:138205"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.1.7601.18777" test_ref="oval:org.mitre.oval:tst:137624"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138543"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.1.7601.22981" test_ref="oval:org.mitre.oval:tst:138480"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.2.9200.17291" test_ref="oval:org.mitre.oval:tst:138549"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138180"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.2.9200.21408" test_ref="oval:org.mitre.oval:tst:138574"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/Server 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Clfsw32.dll is less than 6.3.9600.17719" test_ref="oval:org.mitre.oval:tst:138112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28829" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1713 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1713" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:28.086-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.494-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28822" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer clipboard information disclosure vulnerability - CVE-2015-1692 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1692" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:10.583-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.214-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28821" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-1661 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1661" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:08.311-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:22.648-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:21.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28818" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1733 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1733" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2389 and CVE-2015-2411.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:16.364-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:39.118-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:09.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28816" version="3" class="vulnerability">
      <metadata>
        <title>Registry virtualization elevation of privilege vulnerability - CVE-2015-0073 (MS15-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0073"/>
        <description>The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain privileges via a crafted application, aka "Registry Virtualization Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:19:02.985-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.992-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:25.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138397"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:137988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22943" test_ref="oval:org.mitre.oval:tst:138117"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18738" test_ref="oval:org.mitre.oval:tst:138289"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 (x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21368" test_ref="oval:org.mitre.oval:tst:138325"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 (x64)/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 (x64) / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:138237"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.3.9600.17668" test_ref="oval:org.mitre.oval:tst:138192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28815" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1704 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1704" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1703.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:02.152-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:27.706-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:28.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28808" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1680 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1680"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1678, and CVE-2015-1679.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:25.622-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:27.428-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:28.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28807" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0088 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0088"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0090, CVE-2015-0091, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:58.583-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.571-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28806" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Bitmap handling use after free vulnerability - CVE-2015-1722 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1722"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Bitmap Handling Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:28.704-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:27.917-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:36.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28805" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability - CVE-2015-2377 (MS15-070)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Excel 2007</product>
          <product>Microsoft Excel 2010</product>
          <product>Microsoft Excel 2013</product>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2377"/>
        <description>Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-23T17:34:44">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T13:47:52.634-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:38.887-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:09.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Excel 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2007 is installed" definition_ref="oval:org.mitre.oval:def:1745"/>
          <criterion comment="Check if the version of excel.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:140929"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2010 is installed" definition_ref="oval:org.mitre.oval:def:12658"/>
          <criterion comment="Check if the version of excel.exe is less than 14.0.7153.5000" test_ref="oval:org.mitre.oval:tst:141097"/>
        </criteria>
        <criteria operator="AND" comment="Excel 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Excel 2013 is installed" definition_ref="oval:org.mitre.oval:def:15563"/>
          <criterion comment="Check if the version of excel.exe is less than 15.0.4737.1000" test_ref="oval:org.mitre.oval:tst:141327"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack 2007 and vulnerable version">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="Check if the version of excelcnv.exe is less than 12.0.6723.5000" test_ref="oval:org.mitre.oval:tst:140850"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28804" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2390 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2390" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2390" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2397, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:40.950-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:38.450-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:08.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28803" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0077 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0077"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information from kernel memory, and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:37.910-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.352-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28797" version="6" class="vulnerability">
      <metadata>
        <title>VBScript memory corruption vulnerability - CVE-2015-0032 (MS15-019)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VBScript 5.8</product>
          <product>VBScript 5.7</product>
          <product>VBScript 5.6</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0032" source="CVE"/>
        <description>vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:30.793-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:14.794-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.063-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28797 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:41:00.692-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:45:51.397-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:37.954-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <extend_definition comment="VBScript 5.6 is installed" definition_ref="oval:org.mitre.oval:def:28988"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of vbscript.dll is less than 5.6.0.8854" test_ref="oval:org.mitre.oval:tst:137392"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.23629" test_ref="oval:org.mitre.oval:tst:138317"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.19319" test_ref="oval:org.mitre.oval:tst:137890"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.23629" test_ref="oval:org.mitre.oval:tst:138317"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="IE 6/7">
            <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
            <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23661" test_ref="oval:org.mitre.oval:tst:138368"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19607" test_ref="oval:org.mitre.oval:tst:138131"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23661" test_ref="oval:org.mitre.oval:tst:138368"/>
                  <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="vulnerable file version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18751" test_ref="oval:org.mitre.oval:tst:138241"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.22958" test_ref="oval:org.mitre.oval:tst:138340"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal 5.8.7601.22000" test_ref="oval:org.mitre.oval:tst:113859"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 9 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17138" test_ref="oval:org.mitre.oval:tst:138295"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20748" test_ref="oval:org.mitre.oval:tst:138279"/>
                </criteria>
              </criteria>
              <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17267" test_ref="oval:org.mitre.oval:tst:138005"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21384" test_ref="oval:org.mitre.oval:tst:138137"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17689" test_ref="oval:org.mitre.oval:tst:138385"/>
              <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28783" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1662 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1662" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1659 and CVE-2015-1665.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:12.782-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:21.122-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:20.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28781" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1626 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1626" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0056 and CVE-2015-1623.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:34.504-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:14.575-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28780" version="3" class="vulnerability">
      <metadata>
        <title>Task scheduler security feature bypass vulnerability - CVE-2015-0084 (MS15-028)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0084"/>
        <description>The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended restrictions on launching executable files via a crafted task, aka "Task Scheduler Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:28:14.673-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:14.260-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ubpm.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138109"/>
              <criterion comment="Check if the version of Ubpm.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138316"/>
            </criteria>
            <criterion comment="Check if the version of Ubpm.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:138334"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ubpm.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:137999"/>
              <criterion comment="Check if the version of Ubpm.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138439"/>
            </criteria>
            <criterion comment="Check if the version of Ubpm.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ubpm.dll is less than 6.3.9600.17671" test_ref="oval:org.mitre.oval:tst:138035"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28771" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0092 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0092"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:45:00.714-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.976-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28770" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0090 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0090"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0091, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:53.942-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.784-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28769" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1737 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1737" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1737" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:08.182-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:26.587-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:33.026-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28768" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0056 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0056" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1623 and CVE-2015-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:32.155-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.592-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28767" version="4" class="vulnerability">
      <metadata>
        <title>Group Policy security feature bypass vulnerability - CVE-2015-0009 (MS15-014)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0009"/>
        <description>The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing requirement and trigger a revert-to-default action by spoofing domain-controller responses, aka "Group Policy Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:20:38.547-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43110 - bulletins for the month of February 2015" date="2015-02-16T13:18:00.755-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-03-09T04:01:53.352-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:29.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Scesrv.dll is less than 5.2.3790.5492" test_ref="oval:org.mitre.oval:tst:137802"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.0.6002.23558" test_ref="oval:org.mitre.oval:tst:138116"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137943"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.0.6002.19251" test_ref="oval:org.mitre.oval:tst:138132"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.1.7601.22894" test_ref="oval:org.mitre.oval:tst:137878"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137512"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.1.7601.18686" test_ref="oval:org.mitre.oval:tst:138089"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137843"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138020"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.2.9200.17200" test_ref="oval:org.mitre.oval:tst:138096"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Scesrv.dll is less than 6.3.9600.17552" test_ref="oval:org.mitre.oval:tst:137690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28764" version="3" class="vulnerability">
      <metadata>
        <title>Windows create process elevation of privilege vulnerability - CVE-2015-0062 (MS15-015)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0062"/>
        <description>Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a process that uses the SeAssignPrimaryTokenPrivilege privilege, aka "Windows Create Process Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:22:14.916-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:53.140-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18715" test_ref="oval:org.mitre.oval:tst:137284"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22921" test_ref="oval:org.mitre.oval:tst:137701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17231" test_ref="oval:org.mitre.oval:tst:138000"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:138067"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:138065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28762" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft schannel remote code execution vulnerability - CVE-2015-0003 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0003"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:46.665-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.789-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.275-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:26.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28757" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1622 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1622" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:46.514-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.440-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28753" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1689 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1689" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1705.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:30.439-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:26.222-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:26.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28752" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft office component use after free vulnerability - CVE-2015-1651 (MS15-033)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Office Compatibility Pack</product>
          <product>Microsoft Word Viewer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1651" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1651"/>
        <description>Use-after-free vulnerability in Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T13:58:26">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:09:46.336-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:19.936-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:20.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="Check if the version of winword.exe is less than 12.0.6720.5000" test_ref="oval:org.mitre.oval:tst:138470"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack and vuln file version">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="Check if the version of wordcnv.dll is less than 12.0.6720.5000" test_ref="oval:org.mitre.oval:tst:138309"/>
        </criteria>
        <criteria operator="AND" comment="Word viewer and vulnerable version of file">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="Check if the version of wordview.exe is less than 11.0.8417" test_ref="oval:org.mitre.oval:tst:138052"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28750" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0038 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0038" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0042 and CVE-2015-0046.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:31.933-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.534-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28745" version="6" class="vulnerability">
      <metadata>
        <title>VBScript and JScript ASLR bypass vulnerability - CVE-2015-1686 (MS15-043 and MS15-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>JScript 5.6</product>
          <product>JScript 5.7</product>
          <product>JScript 5.8</product>
          <product>VBScript 5.6</product>
          <product>VBScript 5.7</product>
          <product>VBScript 5.8</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1686" source="CVE"/>
        <description>The Microsoft (1) VBScript 5.6 through 5.8 and (2) JScript 5.6 through 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T17:44:26.144+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:07.977-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.666-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:25.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28745 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:47.704-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:36.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <criteria operator="OR" comment="JScript.dll/VBScript.dll version">
            <extend_definition comment="VBScript 5.6 is installed" definition_ref="oval:org.mitre.oval:def:28988"/>
            <extend_definition comment="JScript 5.6 is installed" definition_ref="oval:org.mitre.oval:def:29034"/>
          </criteria>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="JScript.dll/VBScript.dll version">
            <criterion comment="Check if the version of JScript.dll is less than 5.6.0.8855" test_ref="oval:org.mitre.oval:tst:138607"/>
            <criterion comment="Check if the version of VBScript.dll is less than 5.6.0.8855" test_ref="oval:org.mitre.oval:tst:138604"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <criteria operator="OR" comment="JScript.dll/VBScript.dll 5.7">
            <extend_definition comment="VBScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:29032"/>
            <extend_definition comment="JScript 5.7 is installed" definition_ref="oval:org.mitre.oval:def:28774"/>
          </criteria>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criteria operator="OR" comment="JScript.dll/VBScript.dll version">
                <criterion comment="Check if the version of JScript.dll is less than 5.7.6002.23659" test_ref="oval:org.mitre.oval:tst:138432"/>
                <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23659" test_ref="oval:org.mitre.oval:tst:138320"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.19351" test_ref="oval:org.mitre.oval:tst:138602"/>
                <criterion comment="Check if the version of JScript.dll is less than 5.7.6002.19351" test_ref="oval:org.mitre.oval:tst:138597"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23659" test_ref="oval:org.mitre.oval:tst:138320"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of JScript.dll is less than 5.7.6002.23659" test_ref="oval:org.mitre.oval:tst:138432"/>
                  <criterion comment="Check if the version of JScript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:138362"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <criteria operator="OR" comment="either VBscript 5.8 / JScript 5.8">
            <extend_definition comment="VBScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28109"/>
            <extend_definition comment="JScript 5.8 is installed" definition_ref="oval:org.mitre.oval:def:28817"/>
          </criteria>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2 + IE 8 vulnerable version">
              <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="2k3 and vulnerable version">
                  <criteria operator="OR" comment="2K3">
                    <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                    <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23671" test_ref="oval:org.mitre.oval:tst:138609"/>
                </criteria>
                <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
                  <criteria operator="OR" comment="Vista / 2K8">
                    <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                    <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19612" test_ref="oval:org.mitre.oval:tst:138153"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23671" test_ref="oval:org.mitre.oval:tst:138609"/>
                      <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  </criteria>
                  <criteria operator="OR" comment="vulnerable file version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18806" test_ref="oval:org.mitre.oval:tst:137926"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.23010" test_ref="oval:org.mitre.oval:tst:138242"/>
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.7601.23000" test_ref="oval:org.mitre.oval:tst:138193"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
              <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 9 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of jscript.dll is less than 5.8.7601.17141" test_ref="oval:org.mitre.oval:tst:138378"/>
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17141" test_ref="oval:org.mitre.oval:tst:138375"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20751" test_ref="oval:org.mitre.oval:tst:138459"/>
                </criteria>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of jscript.dll is less than 5.8.7601.20751" test_ref="oval:org.mitre.oval:tst:138538"/>
                  <criterion comment="Check if the version of jscript.dll is greater than or equal to 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:138493"/>
                </criteria>
              </criteria>
              <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of jscript.dll is less than 5.8.9200.17296" test_ref="oval:org.mitre.oval:tst:138472"/>
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17296" test_ref="oval:org.mitre.oval:tst:138269"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of jscript.dll is less than 5.8.9200.21413" test_ref="oval:org.mitre.oval:tst:138629"/>
                      <criterion comment="Check if the version of jscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135737"/>
                    </criteria>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21413" test_ref="oval:org.mitre.oval:tst:138512"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="vuln versions">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17728" test_ref="oval:org.mitre.oval:tst:138586"/>
                <criterion comment="Check if the version of jscript.dll is less than 5.8.9600.17728" test_ref="oval:org.mitre.oval:tst:138405"/>
              </criteria>
              <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28744" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability – CVE-2015-1759 (MS15-059)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Office Compatibility Pack</product>
        </affected>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1759" ref_id="CVE-2015-1759"/>
        <description>Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T12:38:56">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:19:35.354-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:25.003-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:31.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
        <criterion comment="Check if the version of Wpft532.cnv is greater than or equal to 2006.1200.0000.0000" test_ref="oval:org.mitre.oval:tst:87267"/>
        <criterion comment="Check if the version of Wpft532.cnv is less than 2006.1200.6722.5000" test_ref="oval:org.mitre.oval:tst:139062"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28743" version="3" class="vulnerability">
      <metadata>
        <title>Win32k information disclosure vulnerability - CVE-2015-2367 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2367"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from uninitialized kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:51.163-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:36.176-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:08.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28742" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1675 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1675"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:56.931-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.427-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:24.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28739" version="4" class="vulnerability">
      <metadata>
        <title>.NET XML decryption denial of service vulnerability - CVE-2015-1672 (MS15-048)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1672"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted encrypted data in an XML document, aka ".NET XML Decryption Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:35:01.777-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.043-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:24.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28739 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:17.046-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criterion comment="Check if the version of System.Security.dll is less than 2.0.50727.3665" test_ref="oval:org.mitre.oval:tst:138113"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.4256" test_ref="oval:org.mitre.oval:tst:138846"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.6426" test_ref="oval:org.mitre.oval:tst:138697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138758"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.5490" test_ref="oval:org.mitre.oval:tst:138559"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.2056" test_ref="oval:org.mitre.oval:tst:138327"/>
              <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80978"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.1031" test_ref="oval:org.mitre.oval:tst:138792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36288" test_ref="oval:org.mitre.oval:tst:138794"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check fi the version of system.security.dll is less than 4.0.30319.34252" test_ref="oval:org.mitre.oval:tst:138631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138774"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138774"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138577"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28738" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0093 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0093"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0092.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:45:02.924-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.071-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28737" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0072 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:18.057-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.812-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28735" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0044 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference ref_id="CVE-2015-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0044" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0050.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:33.397-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.272-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28732" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0039 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0039" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:36.175-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.070-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28731" version="5" class="vulnerability">
      <metadata>
        <title>TIFF Processing information disclosure vulnerability - CVE-2015-0061 (MS15-016)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0061"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process memory via a crafted image file, aka "TIFF Processing Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:23:35.449-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.816-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28731 - fixed check for Windowscodecs.ddl version" date="2015-04-15T12:25:00.421-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2015-04-15T12:28:01.420-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:18.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23588" test_ref="oval:org.mitre.oval:tst:137169"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
              <criterion comment="Check if the version Windowscodecs.dll of is less than 7.0.6002.23591" test_ref="oval:org.mitre.oval:tst:138070"/>
            </criteria>
            <criterion comment="Check if the version Windowscodecs.dll of is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138090"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Windowscodecs.dll is 6.1 or 6.2">
            <criteria comment="6.2">
              <criterion comment="Check if the version Windowscodecs.dll of is greater than 6.2" test_ref="oval:org.mitre.oval:tst:137662"/>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
                  <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137952"/>
                </criteria>
                <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:137222"/>
              </criteria>
            </criteria>
            <criteria comment="6.1">
              <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2" test_ref="oval:org.mitre.oval:tst:138040"/>
              <criteria operator="OR" comment="either file versions">
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22922" test_ref="oval:org.mitre.oval:tst:138081"/>
                  <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
                </criteria>
                <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18716" test_ref="oval:org.mitre.oval:tst:137954"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.21345" test_ref="oval:org.mitre.oval:tst:138119"/>
            </criteria>
            <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.17228" test_ref="oval:org.mitre.oval:tst:137975"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version Windowscodecs.dll of is less than 6.3.9600.17631" test_ref="oval:org.mitre.oval:tst:137585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28730" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver denial of service vulnerability - CVE-2015-0074 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0074"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted (1) web site or (2) file, aka "Adobe Font Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:46.568-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.601-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28728" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0055 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0055" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:43.195-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.473-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28724" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1754 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference ref_id="CVE-2015-1754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1754" source="CVE"/>
        <description>Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:02.186-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:23.768-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:29.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="vulnerable os and their respective file versions">
          <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
            <criteria operator="OR" comment="2k3(x86 + x64)">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
          </criteria>
          <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
            <criteria operator="OR" comment="Vista/ 2k8">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28723" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Office memory corruption vulnerability – CVE-2015-1683 (MS15-046)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Office 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1683" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1683"/>
        <description>Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:50:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:06:11.856-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:24.892-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:23.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
        <criterion comment="Check if the version of mso.dll is less than 12.0.6721.5000" test_ref="oval:org.mitre.oval:tst:138288"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28718" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0022 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0022" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:07.271-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.071-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28717" version="3" class="vulnerability">
      <metadata>
        <title>Directory Traversal elevation of privilege vulnerability - CVE-2015-0016 (MS15-004)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows Remote Desktop Connection 7.0</product>
          <product>Microsoft Windows Remote Desktop Connection 8.0</product>
          <product>Microsoft Windows Remote Desktop Connection 8.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0016"/>
        <description>Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:19:16.598-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:37.791-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:33.966-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / Remote Desktop 7.0 / vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Remote Desktop 7.0 and Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7600.17715" test_ref="oval:org.mitre.oval:tst:137087"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7600.00000" test_ref="oval:org.mitre.oval:tst:136870"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7600.21000" test_ref="oval:org.mitre.oval:tst:137555"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7600.21909" test_ref="oval:org.mitre.oval:tst:137523"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.18699" test_ref="oval:org.mitre.oval:tst:137471"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137404"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.22907" test_ref="oval:org.mitre.oval:tst:137490"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.0 and vulnerable version">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.17212" test_ref="oval:org.mitre.oval:tst:137630"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137557"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.0 and Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:136901"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.21329" test_ref="oval:org.mitre.oval:tst:136668"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.1 and vulnerable version">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.3.9600.17553" test_ref="oval:org.mitre.oval:tst:136858"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.3.9600.00000" test_ref="oval:org.mitre.oval:tst:137545"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2008 R2 IA64 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.18699" test_ref="oval:org.mitre.oval:tst:137471"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137404"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.22907" test_ref="oval:org.mitre.oval:tst:137490"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.17213" test_ref="oval:org.mitre.oval:tst:137622"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:136901"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.21329" test_ref="oval:org.mitre.oval:tst:136668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Tswbprxy.exe is less than 6.3.9600.17555" test_ref="oval:org.mitre.oval:tst:137058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28714" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0025 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0025" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0023.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:11.825-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.861-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <criteria operator="AND" comment="Win 7/R2">
            <criteria operator="OR" comment="Win 7/R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8/ 2012 R2">
            <criteria operator="OR" comment="Win 8/ 2012">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28711" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0020 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0020" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:08.991-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.416-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28710" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1696 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1696"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:52.133-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:24.609-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:23.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28709" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1665 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1665" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1665" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1659 and CVE-2015-1662.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:02.972-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:18.790-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:19.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28708" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component EOP vulnerability - CVE-2015-2364 (MS15-072)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2364"/>
        <description>The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that leverages an incorrect bitmap conversion, aka "Graphics Component EOP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T20:35:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:24:06.820-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:35.282-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:07.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 vulnerable version">
          <criteria operator="OR" comment="Server (2003 - x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 5.2.3790.5661" test_ref="oval:org.mitre.oval:tst:140966"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.19421" test_ref="oval:org.mitre.oval:tst:141236"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87308"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.23728" test_ref="oval:org.mitre.oval:tst:140635"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.18898" test_ref="oval:org.mitre.oval:tst:141266"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:87215"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.23100" test_ref="oval:org.mitre.oval:tst:141108"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.2.9200.17410" test_ref="oval:org.mitre.oval:tst:141167"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gdi32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114810"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.2.9200.21521" test_ref="oval:org.mitre.oval:tst:141249"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 6.3.9600.17902" test_ref="oval:org.mitre.oval:tst:141114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28704" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1657 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1657" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:22.070-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:18.550-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:19.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28700" version="3" class="vulnerability">
      <metadata>
        <title>Group Policy remote code execution vulnerability - CVE-2015-0008 (MS15-011)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0008"/>
        <description>The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:15:28.177-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.064-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:137915"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Gpsvc.dll is less than 6.1.7601.22917" test_ref="oval:org.mitre.oval:tst:137883"/>
              <criterion comment="Check if the version of Gpsvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137655"/>
            </criteria>
            <criterion comment="Check if the version of Gpsvc.dll is less than 6.1.7601.18711" test_ref="oval:org.mitre.oval:tst:137989"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Gpsvc.dll is less than 6.2.9200.21339" test_ref="oval:org.mitre.oval:tst:137798"/>
              <criterion comment="Check if the version of Gpsvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137613"/>
            </criteria>
            <criterion comment="Check if the version of Gpsvc.dll is less than 6.2.9200.17225" test_ref="oval:org.mitre.oval:tst:137951"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Gpsvc.dll is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:138043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28695" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0049 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0049" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:10:54.028-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.793-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28694" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: WTS remote code execution vulnerability - CVE-2015-0081 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0081"/>
        <description>Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:40:13.969-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.328-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.040-04:00">ACCEPTED</status_change>
            <modified comment="Duplicate of 27987" date="2015-05-06T14:09:19.017-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2015-05-06T14:09:19.017-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msctf.dll is less than 5.2.3790.5528" test_ref="oval:org.mitre.oval:tst:138239"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.19296" test_ref="oval:org.mitre.oval:tst:138034"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138111"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.23606" test_ref="oval:org.mitre.oval:tst:137872"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.18731" test_ref="oval:org.mitre.oval:tst:138101"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138359"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.22937" test_ref="oval:org.mitre.oval:tst:138352"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.17243" test_ref="oval:org.mitre.oval:tst:138103"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138024"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.21361" test_ref="oval:org.mitre.oval:tst:138146"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version msctf.dll is less than 6.3.9600.17664" test_ref="oval:org.mitre.oval:tst:138158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28692" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1703 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1703" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1704.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:27.260-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:23.965-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:22.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28691" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0045 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0045" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0053.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:35.064-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.533-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.264-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28690" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft office component use after free vulnerability - CVE-2015-1649 (MS15-033)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Word 2007</product>
          <product>Microsoft Word 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps 2010</product>
          <product>Microsoft Office Compatibility Pack</product>
          <product>Microsoft Word Viewer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1649" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1649"/>
        <description>Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T13:58:26">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:09:51.754-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:18.354-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:19.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Word 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2007 is installed" definition_ref="oval:org.mitre.oval:def:2074"/>
          <criterion comment="Check if the version of winword.exe is less than 12.0.6720.5000" test_ref="oval:org.mitre.oval:tst:138470"/>
        </criteria>
        <criteria operator="AND" comment="Word 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Word 2010 is installed" definition_ref="oval:org.mitre.oval:def:7631"/>
          <criterion comment="Check if the version of winword.exe is less than 14.0.7147.5000" test_ref="oval:org.mitre.oval:tst:138418"/>
        </criteria>
        <criteria operator="AND" comment="Office Compatibility Pack and vuln file version">
          <extend_definition comment="Microsoft Office Compatibility Pack is installed" definition_ref="oval:org.mitre.oval:def:1853"/>
          <criterion comment="Check if the version of wordcnv.dll is less than 12.0.6720.5000" test_ref="oval:org.mitre.oval:tst:138309"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of sword.dll is less than 14.0.7147.5000" test_ref="oval:org.mitre.oval:tst:138110"/>
        </criteria>
        <criteria operator="AND" comment="Web Apps 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
          <criterion comment="Check if the version of sword.dll is less than 14.0.7147.5000" test_ref="oval:org.mitre.oval:tst:137535"/>
        </criteria>
        <criteria operator="AND" comment="Word viewer and vulnerable version of file">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="Check if the version of wordview.exe is less than 11.0.8417" test_ref="oval:org.mitre.oval:tst:138052"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28689" version="5" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-0057 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0057"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:48.608-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.214-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.638-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:23.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28688" version="5" class="vulnerability">
      <metadata>
        <title>Windows font driver denial of service vulnerability - CVE-2015-0060 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0060"/>
        <description>The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Windows Font Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:51.771-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.917-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.858-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:23.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28684" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0091 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0091"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:51.497-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.060-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28683" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0052 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0052" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0039, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:29.508-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.699-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28680" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1714 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1714" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1714" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:18.628-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:22.964-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:21.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28675" version="3" class="vulnerability">
      <metadata>
        <title>JPEG XR parser information disclosure vulnerability - CVE-2015-0076 (MS15-029)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0076"/>
        <description>The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "JPEG XR Parser Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:32:06.528-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.733-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 7.0.6002.19299" test_ref="oval:org.mitre.oval:tst:137741"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138411"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 7.0.6002.23609" test_ref="oval:org.mitre.oval:tst:138249"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.18742" test_ref="oval:org.mitre.oval:tst:138361"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138077"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.22949" test_ref="oval:org.mitre.oval:tst:137949"/>
            </criteria>
            <criteria operator="AND" comment="Wmphoto.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.21371" test_ref="oval:org.mitre.oval:tst:137649"/>
                  <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138341"/>
                </criteria>
                <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.17254" test_ref="oval:org.mitre.oval:tst:137935"/>
              </criteria>
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:138413"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Server 2008 R2 IA64 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.18742" test_ref="oval:org.mitre.oval:tst:138361"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138077"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.22949" test_ref="oval:org.mitre.oval:tst:137949"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138074"/>
        