<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2015-09-03T06:24:39.222-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:29115" version="3" class="vulnerability">
      <metadata>
        <title>Exchange Cross-Site Request Forgery vulnerability - CVE-2015-1771 (MS15-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1771"/>
        <description>Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:51.667-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:17.668-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:53.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.41" test_ref="oval:org.mitre.oval:tst:139078"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU8 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 8 is installed" definition_ref="oval:org.mitre.oval:def:29138"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" test_ref="oval:org.mitre.oval:tst:139030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28928" version="3" class="vulnerability">
      <metadata>
        <title>Exchange HTML injection vulnerability - CVE-2015-2359 (MS15-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2359"/>
        <description>Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Exchange HTML Injection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:52.070-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:14.350-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:50.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 8 is installed" definition_ref="oval:org.mitre.oval:def:29138"/>
        <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" test_ref="oval:org.mitre.oval:tst:139030"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28924" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint page content vulnerabilities – CVE-2015-1700 (MS15-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Server 2007</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1700"/>
        <description>Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T20:21:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:09:54.328-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-06-15T04:00:30.063-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint 2007 and vulnerable file versions">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="Check if the version of Microsoft.SharePoint.Portal.dll is less than 12.0.6721.5000" test_ref="oval:org.mitre.oval:tst:137831"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of Microsoft.office.policy.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138630"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2010 / 2010 SP1">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138555"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4719.1002" test_ref="oval:org.mitre.oval:tst:138608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2313" version="12" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2007 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2007"/>
        <description>Microsoft Office SharePoint Server 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:51.975-04:00">DRAFT</status_change>
            <status_change date="2007-10-26T10:00:30.934-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:08.127-05:00">ACCEPTED</status_change>
            <modified comment="Changed datatype from version to string." date="2008-08-28T13:32:00.278-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-08-28T13:44:16.491-04:00">INTERIM</status_change>
            <status_change date="2008-09-15T04:00:21.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:38.747-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:18.536-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.072-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.072-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:00.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:25.573-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:03.519-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:36.194-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - removed Microsoft Exchange Server 2003 from inventory" date="2015-06-05T09:04:00.152-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-05T09:06:27.662-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:42.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:4279"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28811" version="3" class="vulnerability">
      <metadata>
        <title>OWA modified canary parameter cross site scripting vulnerability - CVE-2015-1628 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1628"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted X-OWA-Canary cookie in an AD.RecipientType.User action, aka "OWA Modified Canary Parameter Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:14.964-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.759-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:25.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28748" version="3" class="vulnerability">
      <metadata>
        <title>ExchangeDLP cross site scripting vulnerability - CVE-2015-1629 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1629" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1629"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "ExchangeDLP Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:15.740-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.291-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28658" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint xss vulnerability – CVE-2015-1636 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1636"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T09:59:52.885-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.162-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:19.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.611-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:22.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint Foundation Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138170"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138254"/>
            <criterion comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" test_ref="oval:org.mitre.oval:tst:138441"/>
            <criterion comment="Check if the version of vutils.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138393"/>
            <criterion comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138339"/>
            <criterion comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" test_ref="oval:org.mitre.oval:tst:138351"/>
            <criterion comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" test_ref="oval:org.mitre.oval:tst:138449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28607" version="3" class="vulnerability">
      <metadata>
        <title>Exchange Server-Side Request Forgery vulnerability - CVE-2015-1764 (MS15-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1764"/>
        <description>The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origin Policy and send HTTP traffic to intranet servers via a crafted request, related to a Server-Side Request Forgery (SSRF) issue, aka "Exchange Server-Side Request Forgery Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:51.904-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:11.617-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:49.943-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.41" test_ref="oval:org.mitre.oval:tst:139078"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU8 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 8 is installed" definition_ref="oval:org.mitre.oval:def:29138"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" test_ref="oval:org.mitre.oval:tst:139030"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29138" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 8 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu8"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 8 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T18:41:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:10:51.193-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:18.099-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:53.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 Cumulative Update 8 is installed" test_ref="oval:org.mitre.oval:tst:138824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28524" version="3" class="vulnerability">
      <metadata>
        <title>Audit report cross site scripting vulnerability - CVE-2015-1630 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1630"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Audit Report Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:14.215-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.617-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:15.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28523" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint XSS vulnerability – CVE-2015-1653 (MS15-036)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1653" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1653"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:26:54.953-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:14.929-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:17.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if the version of Microsoft.Office.Server.Search.dll is less than 15.0.4711.1000" test_ref="oval:org.mitre.oval:tst:137998"/>
        <criteria operator="OR" comment="Either SharePoint Server 2013 / SharePoint Foundation 2013">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28425" version="3" class="vulnerability">
      <metadata>
        <title>Outlook Web App token spoofing vulnerability (CVE-2014-6319) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6319"/>
        <description>Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:20.948-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.958-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:43.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 (no Service Pack) is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.03.0389.002" test_ref="oval:org.mitre.oval:tst:135507"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:15107"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.03.0224.001" test_ref="oval:org.mitre.oval:tst:135743"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1641" version="5" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2007 (no Service Pack) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2007:gold"/>
        <description>Exchange Server 2007 (no Service Pack) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.310-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:35.112-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.621-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:06.842-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:00.696-05:00">ACCEPTED</status_change>
            <modified comment="The method it was using to check for lack of a service pack is not valid for Exchange 2007." date="2008-07-11T11:14:00.045-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2008-07-11T11:18:44.060-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:05.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1641 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:54.126-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:33.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Exchange Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:8521"/>
        <criterion comment="No Exchange Server 2007 SP is installed." test_ref="oval:org.mitre.oval:tst:8498"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15107" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010"/>
        <description>Microsoft Exchange Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-04-04T12:52:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2012-04-06T11:34:21.490-04:00">DRAFT</status_change>
            <status_change date="2012-04-23T04:00:13.600-04:00">INTERIM</status_change>
            <status_change date="2012-05-14T04:00:06.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28415" version="3" class="vulnerability">
      <metadata>
        <title>Exchange URL redirection vulnerability (CVE-2014-6336) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6336" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6336"/>
        <description>Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:17.070-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.340-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:42.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28328" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS vulnerability (CVE-2014-6326) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6326"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6325.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:18.138-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:32.118-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:35.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28294" version="3" class="vulnerability">
      <metadata>
        <title>Exchange forged meeting request spoofing vulnerability  - CVE-2015-1631 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1631" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1631"/>
        <description>Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:15.438-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:06.415-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:12.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28291" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS vulnerability (CVE-2014-6325) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6325" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6325"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6326.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:19.017-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:28.586-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:32.459-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28213" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 CU 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu6"/>
        <description>Microsoft Exchange Server 2013 CU 6 is installed. Microsoft Exchange Server is calendaring software, a mail server and contact manager developed by Microsoft.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T14:23:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:16.589-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:24.485-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:28.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
        <criterion comment="Microsoft Exchange Server Cumulative Update 6 is installed" test_ref="oval:org.mitre.oval:tst:135802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27900" version="3" class="vulnerability">
      <metadata>
        <title>Exchange error message cross site scripting vulnerability - CVE-2015-1632 (MS15-026)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1632"/>
        <description>Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:14.644-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:05.298-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:12.014-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.847.38" test_ref="oval:org.mitre.oval:tst:138401"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU7 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 7 is installed" definition_ref="oval:org.mitre.oval:def:28846"/>
          <criterion comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" test_ref="oval:org.mitre.oval:tst:138053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28846" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 7 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu7"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 7 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:30:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:22:13.692-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.874-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.847-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 Cumulative Update 7 is installed" test_ref="oval:org.mitre.oval:tst:138458"/>
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27875" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint xss vulnerability – CVE-2015-1633 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1633"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T10:00:06.481-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:04.604-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:11.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.846-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:12.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7145.5000" test_ref="oval:org.mitre.oval:tst:138365"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138170"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138254"/>
            <criterion comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" test_ref="oval:org.mitre.oval:tst:138441"/>
            <criterion comment="Check if the version of vutils.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138393"/>
            <criterion comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138339"/>
            <criterion comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" test_ref="oval:org.mitre.oval:tst:138351"/>
            <criterion comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" test_ref="oval:org.mitre.oval:tst:138449"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7145.5000" test_ref="oval:org.mitre.oval:tst:138454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27824" version="4" class="vulnerability">
      <metadata>
        <title>SharePoint elevation of privilege vulnerability - CVE-2014-4116 (MS14-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4116"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:39:40">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:29:43.671-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-12-08T04:00:50.207-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:19.171-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if the version of Onetutil.dll is less than 14.0.7137.5000" test_ref="oval:org.mitre.oval:tst:134500"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26680" version="3" class="vulnerability">
      <metadata>
        <title>Lync Denial of Service vulnerability (CVE-2014-4068) - MS14-055</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2013</product>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4068"/>
        <description>The Response Group Service in Microsoft Lync Server 2010 and 2013 and the Core Components in Lync Server 2013 do not properly handle exceptions, which allows remote attackers to cause a denial of service (daemon hang) via a crafted call, aka "Lync Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T17:08:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:56.842-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.073-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:22.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Lync server 2013 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16524"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 5.0.8308.803" test_ref="oval:org.mitre.oval:tst:123294"/>
            <criterion comment="Check if the version of Deploy.resources.dll is less than 5.0.8308.420" test_ref="oval:org.mitre.oval:tst:123329"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Lync server 2010 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:26794"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of wrtces.dll is less than 4.0.7577.230" test_ref="oval:org.mitre.oval:tst:123304"/>
            <criterion comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 4.0.7577.276" test_ref="oval:org.mitre.oval:tst:122801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26550" version="3" class="vulnerability">
      <metadata>
        <title>Lync Denial of Service vulnerability (CVE-2014-4071) - MS14-055</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2013</product>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4071"/>
        <description>The Server in Microsoft Lync Server 2013 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon hang) via a crafted request, aka "Lync Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T17:08:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:56.412-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:45.038-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:01.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Lync server 2013 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16524"/>
          <criterion comment="Check if the version of SIPStack.dll is less than 5.0.8308.803" test_ref="oval:org.mitre.oval:tst:123219"/>
        </criteria>
        <criteria operator="AND" comment="Lync server 2010 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:26794"/>
          <criterion comment="Check if the version of wrtces.dll is less than 4.0.7577.230" test_ref="oval:org.mitre.oval:tst:123304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26794" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_server:2010"/>
        <description>Microsoft Lync Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T15:07:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:55.728-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:06.363-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:36.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:123575"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16524" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Lync Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_server:2013"/>
        <description>Microsoft Lync Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T15:07:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:55:37.927-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:08.247-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:49.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:81027"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26378" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability allows remote attackers to bypass Protected Mode</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1347"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:40.643-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:19.262-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:27.454-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26378 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:47.467-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:27.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16722" test_ref="oval:org.mitre.oval:tst:42403"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
            <criterion comment="Mshtml.dll version is less than 8.0.7600.20861" test_ref="oval:org.mitre.oval:tst:42393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26317" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to spoof web sites via a crafted HTML document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1451"/>
        <description>Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary host, followed by an HTTPS request to a trusted host and then an HTTP request to an untrusted host, a related issue to CVE-2013-1450.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:45.045-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:18.248-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:25.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26308" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1450"/>
        <description>Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:35.872-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:18.073-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:25.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11985" version="9" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 9 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:9"/>
        <description>A version of Microsoft Internet Explorer 9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-15T15:15:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-03-16T11:15:52.347-04:00">DRAFT</status_change>
            <status_change date="2011-04-04T04:00:07.004-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:07.313-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:00:36.550-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12091 - New Microsoft Patch Tuesday December 2012 definitions." date="2012-12-12T18:47:00.575-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T18:55:58.342-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:00:07.525-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.975-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:10.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26300" version="3" class="vulnerability">
      <metadata>
        <title>SharePoint Page Content Vulnerability (CVE-2014-2816) - MS14-050</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2816"/>
        <description>Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the SharePoint extensibility model, aka "SharePoint Page Content Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:05:02.551-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:54.428-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.051-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Sharepoint Server or Foundation 2013">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
        </criteria>
        <criterion comment="Check if the version of wsssetup.dll is less than 15.0.4641.1000" test_ref="oval:org.mitre.oval:tst:121842"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25633" version="5" class="vulnerability">
      <metadata>
        <title>Arbitrary code executing via unknown vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1346"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:36.855-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:12.433-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:13.514-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25633 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:44.917-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:25.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16722" test_ref="oval:org.mitre.oval:tst:42403"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
            <criterion comment="Mshtml.dll version is less than 8.0.7600.20861" test_ref="oval:org.mitre.oval:tst:42393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6210" version="7" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 8 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:8"/>
        <description>A version of Microsoft Internet Explorer 8 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-23T10:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-23T10:43:47.804-04:00">DRAFT</status_change>
            <status_change date="2009-04-13T04:00:28.239-04:00">INTERIM</status_change>
            <status_change date="2009-05-04T04:00:36.679-04:00">ACCEPTED</status_change>
            <modified comment="Added additional affected platfroms" date="2009-09-24T11:17:00.434-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-09-28T04:00:32.351-04:00">INTERIM</status_change>
            <status_change date="2009-10-26T04:00:04.951-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.728-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.728-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:10.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6210 - modified inventory of Internet Explorer 8" date="2014-01-21T17:03:00.601-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-21T17:05:26.764-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-24T04:03:24.451-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25184" version="5" class="vulnerability">
      <metadata>
        <title>Service Bus Denial of Service Vulnerability - CVE-2014-2814 (MS14-042)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Service Bus 1.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2814"/>
        <description>Microsoft Service Bus 1.1 on Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (AMQP messaging outage) via crafted AMQP messages, aka "Service Bus Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T11:54:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:54:52.877-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:51.944-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:27.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Service Bus 1.1 is installed" definition_ref="oval:org.mitre.oval:def:24926"/>
        <criterion comment="Check if the version of Microsoft.ServiceBus.dll is less than 2.1.40512.2" test_ref="oval:org.mitre.oval:tst:115300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24926" version="3" class="inventory">
      <metadata>
        <title>Microsoft Service Bus 1.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Service Bus 1.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:service_bus:1.1"/>
        <description>Microsoft Service Bus 1.1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T11:54:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:54:52.836-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:39.303-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:56.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Server Bus 1.1 is installed" test_ref="oval:org.mitre.oval:tst:114968"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24787" version="3" class="vulnerability">
      <metadata>
        <title>Web Applications Page Content Vulnerability (CVE-2014-1813) - MS14-022</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1813"/>
        <description>Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applications Page Content Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:06.381-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:16.303-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:20.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="office web apps sp1/sp2">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19186"/>
        </criteria>
        <criterion comment="Check if the version of SWORD.DLL is less than 14.0.7123.5000" test_ref="oval:org.mitre.oval:tst:114167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24618" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2441"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-04-18T14:38:40.749-04:00">DRAFT</status_change>
            <status_change date="2014-05-05T04:00:24.278-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:28.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.30" test_ref="oval:org.mitre.oval:tst:113796"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.22" test_ref="oval:org.mitre.oval:tst:113462"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.8" test_ref="oval:org.mitre.oval:tst:113616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24480" version="3" class="vulnerability">
      <metadata>
        <title>SharePoint XSS Vulnerability (CVE-2014-1754) - MS14-022</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
          <product>Microsoft Office Web Apps Server 2013</product>
          <product>Microsoft SharePoint Server 2013 Client Components SDK</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1754"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:08.488-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:11.888-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:15.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="foundation 2013/version">
          <criterion comment="Check if the version of Microsoft.Office.Server.Msg.dll is less than 15.0.4514.1000" test_ref="oval:org.mitre.oval:tst:114603"/>
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
            <extend_definition comment="Microsoft SharePoint Server 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24462"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2013/version">
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24685"/>
          </criteria>
          <criteria operator="OR" comment="either versions">
            <criterion comment="Check if the version of wsssetup.dll is less than 15.0.4615.1000" test_ref="oval:org.mitre.oval:tst:113960"/>
            <criterion comment="Check if the version of wsetupui.dll is less than 15.0.4561.1000" test_ref="oval:org.mitre.oval:tst:114600"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="web apps server 2013/version">
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
            <extend_definition comment="Microsoft Office Web Apps Server 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24530"/>
          </criteria>
          <criterion comment="Check if the version of msoserver.dll is less than 15.0.4615.1000" test_ref="oval:org.mitre.oval:tst:114430"/>
        </criteria>
        <criteria operator="AND" comment="SharePoint Server 2013 Client Components SDK/version">
          <extend_definition comment="Microsoft SharePoint Server 2013 Client Components SDK is installed" definition_ref="oval:org.mitre.oval:def:24752"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.client.dll is less than 15.0.4609.1000" test_ref="oval:org.mitre.oval:tst:114066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24752" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 Client Components SDK is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft SharePoint Server 2013 Client Components SDK</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server_client_components_sdk:2013"/>
        <description>Microsoft SharePoint Server 2013 Client Components SDK is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T16:15:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:05.214-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:15.775-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:19.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft SharePoint Server 2013 Client Components SDK is installed" test_ref="oval:org.mitre.oval:tst:114587"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24685" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2013:sp1"/>
        <description>Microsoft SharePoint Foundation 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:04.107-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:13.760-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:18.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39142 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.534-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:43.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Sharepoint server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114158"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24530" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps Server 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Office Web Apps Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2013:sp1"/>
        <description>Microsoft Office Web Apps Server 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:04.569-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39205 - regular expression fixes" date="2014-06-10T14:50:00.707-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:10:22.150-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:22.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39205 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:35.894-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:32.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Web Apps Server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114300"/>
        <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24462" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2013:sp1"/>
        <description>Microsoft SharePoint Server 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:03.977-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:11.763-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:14.552-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39142 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.577-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:31.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Sharepoint server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114158"/>
        <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24120" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in the VirtualBox component in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server (CVE-2014-0981)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0981"/>
        <description>VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption.  NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-04-04T10:24:42.126-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:37.090-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:33.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:113418"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" test_ref="oval:org.mitre.oval:tst:113364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24026" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in the VirtualBox component in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server (CVE-2014-0983)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0983"/>
        <description>Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-04-04T10:24:41.750-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:34.902-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:30.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:113418"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" test_ref="oval:org.mitre.oval:tst:113364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22434" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability, a different vulnerability than CVE-2014-0404</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0406"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:45.576-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:27.944-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:09.043-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22409" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5892"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:03:17">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-30T14:49:20.533-05:00">DRAFT</status_change>
            <status_change date="2014-02-17T04:01:38.405-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:43.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:100260"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.4" test_ref="oval:org.mitre.oval:tst:100012"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22391" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability, a different vulnerability than CVE-2014-0406</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0404"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:45.953-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:27.690-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:07.094-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21883" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0407" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0407"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:46.749-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:22.299-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:02.226-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21438" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0405" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0405"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:46.316-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:21.478-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:00.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11581" version="9" class="inventory">
      <metadata>
        <title>VirtualBox is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:oracle:xvm_virtualbox"/>
        <description>VirtualBox is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-12-17T19:26:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-21T11:27:26.795-05:00">DRAFT</status_change>
            <status_change date="2011-01-10T04:00:04.930-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:03.574-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11581 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:37.133-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:03.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11581 - Found a few issues with the current inventory definition for VirtualBox and the vulnerability definition which uses it, and the fixes plus a bit more are attached. The core issue is that the registry key where the relevant information is stored has had 4 different values since version 3.0.0, with the most recent change causing the vulnerability definition to throw an error." date="2011-10-17T13:02:00.116-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T13:24:26.817-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:09.278-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.057-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:06.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if Sun xVM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:41938"/>
        <criterion comment="Check if Sun VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:44050"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21058" version="4" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities (CVE-2013-5763) - MS13-105</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Exchange Server 2013</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5763"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance.  NOTE: the original disclosure of this issue erroneously mapped it to CVE-2013-3624.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T12:19:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-13T11:13:50.869-05:00">DRAFT</status_change>
            <status_change date="2013-12-30T04:01:01.737-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:18.527-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.3.342.4" test_ref="oval:org.mitre.oval:tst:89886"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of exsetup.exe is less than 14.2.390.3" test_ref="oval:org.mitre.oval:tst:89663"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP3 is installed" definition_ref="oval:org.mitre.oval:def:17932"/>
          <criterion comment="Check if the version of exsetup.exe is less than 14.3.174.1" test_ref="oval:org.mitre.oval:tst:89845"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 2 is installed" definition_ref="oval:org.mitre.oval:def:18484"/>
          <criterion comment="Check if the version of exsetup.exe is less than 15.0.712.31" test_ref="oval:org.mitre.oval:tst:89888"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 3 is installed" definition_ref="oval:org.mitre.oval:def:20878"/>
          <criterion comment="Check if the version of exsetup.exe is less than 15.0.775.41" test_ref="oval:org.mitre.oval:tst:89992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20798" version="5" class="vulnerability">
      <metadata>
        <title>SignalR XSS Vulnerability (CVE-2013-5042) - MS13-103</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Visual Studio Team Foundation Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5042"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T19:38:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:27:45.400-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.490-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.500-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:31.970-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Visual Studio Team Foundation Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:20854"/>
        <criterion comment="Check if the version of Microsoft.AspNet.SignalR.Core.dll is less than 1.1.21022.0" test_ref="oval:org.mitre.oval:tst:89989"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20854" version="4" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio Team Foundation Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Visual Studio Team Foundation Server</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_team_foundation_server:2013"/>
        <description>Microsoft Visual Studio Team Foundation Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T19:38:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:27:45.255-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.786-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.721-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:37.681-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Visual Studio Team Foundation Server is installed" test_ref="oval:org.mitre.oval:tst:90023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20769" version="6" class="vulnerability">
      <metadata>
        <title>SharePoint Page Content Vulnerabilities (CVE-2013-5059) - MS13-100</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
          <product>Microsoft Office Web Apps Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5059"/>
        <description>Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T13:31:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:23:40.189-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.057-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.218-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:29.330-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20769 - update for office web apps server 2013 in ms13-100." date="2014-02-04T12:29:00.924-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2014-02-04T12:31:06.140-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:33.801-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/sp1/sp2 and file version">
          <criteria operator="OR" comment="sharepoint server 2010/sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criterion comment="Check if the version of ascalc.dll is less than 14.0.7011.1000" test_ref="oval:org.mitre.oval:tst:90029"/>
        </criteria>
        <criteria operator="AND" comment="foundation 2013/version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criterion comment="Check if the version of ascalc.dll is less than 15.0.4545.1000" test_ref="oval:org.mitre.oval:tst:89884"/>
        </criteria>
        <criteria operator="AND" comment="web apps 2013">
          <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
          <criterion comment="Msoserver.Dll is less than 15.0.4551.1007" test_ref="oval:org.mitre.oval:tst:100103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22312" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Office Web Apps Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2013"/>
        <description>Microsoft Office Web Apps Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T14:16:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-01-21T17:03:41.194-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:25.770-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:05.741-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Msoserver.dll is present" test_ref="oval:org.mitre.oval:tst:99831"/>
        <criterion comment="Check for the existence of SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.WacServer" test_ref="oval:org.mitre.oval:tst:100108"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20653" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS Vulnerability (CVE-2013-5072) - MS13-105</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5072"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T12:19:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-13T11:13:50.156-05:00">DRAFT</status_change>
            <status_change date="2013-12-30T04:00:49.514-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:04.987-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.3.342.4" test_ref="oval:org.mitre.oval:tst:89886"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of exsetup.exe is less than 14.2.390.3" test_ref="oval:org.mitre.oval:tst:89663"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP3 is installed" definition_ref="oval:org.mitre.oval:def:17932"/>
          <criterion comment="Check if the version of exsetup.exe is less than 14.3.174.1" test_ref="oval:org.mitre.oval:tst:89845"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 2 is installed" definition_ref="oval:org.mitre.oval:def:18484"/>
          <criterion comment="Check if the version of exsetup.exe is less than 15.0.712.31" test_ref="oval:org.mitre.oval:tst:89888"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 3 is installed" definition_ref="oval:org.mitre.oval:def:20878"/>
          <criterion comment="Check if the version of exsetup.exe is less than 15.0.775.41" test_ref="oval:org.mitre.oval:tst:89992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20083" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities (CVE-2013-5791) - MS13-105</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5791"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.  NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is a stack-based buffer overflow in the Microsoft Access 1.x parser in vsacs.dll before 8.4.0.108 and before 8.4.1.52, which allows attackers to execute arbitrary code via a long field (aka column) name.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T12:19:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-13T11:13:51.440-05:00">DRAFT</status_change>
            <status_change date="2013-12-30T04:00:32.522-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:00:30.068-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.3.342.4" test_ref="oval:org.mitre.oval:tst:89886"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of exsetup.exe is less than 14.2.390.3" test_ref="oval:org.mitre.oval:tst:89663"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP3 is installed" definition_ref="oval:org.mitre.oval:def:17932"/>
          <criterion comment="Check if the version of exsetup.exe is less than 14.3.174.1" test_ref="oval:org.mitre.oval:tst:89845"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 2 is installed" definition_ref="oval:org.mitre.oval:def:18484"/>
          <criterion comment="Check if the version of exsetup.exe is less than 15.0.712.31" test_ref="oval:org.mitre.oval:tst:89888"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 3 is installed" definition_ref="oval:org.mitre.oval:def:20878"/>
          <criterion comment="Check if the version of exsetup.exe is less than 15.0.775.41" test_ref="oval:org.mitre.oval:tst:89992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20878" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu3"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 3 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-11T13:04:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-13T11:13:50.125-05:00">DRAFT</status_change>
            <status_change date="2013-12-30T04:00:58.676-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:14.300-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
        <criterion comment="Check if Exchange Server 2013 Cumulative Update 3 is installed" test_ref="oval:org.mitre.oval:tst:89964"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19136" version="9" class="vulnerability">
      <metadata>
        <title>Cross-site scripting vulnerability in Microsoft SharePoint (CVE-2013-3180) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3180"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:44.387-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:51.214-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:27.136-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19136 - updated to check proper version as per bulletin." date="2014-01-16T10:58:00.923-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-16T10:59:41.814-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:01:12.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.370-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:16.378-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.946-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:11.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="foundation 2010/version">
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7105.5000" test_ref="oval:org.mitre.oval:tst:87199"/>
          <criteria operator="OR" comment="foundation 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <criteria operator="OR" comment="sharepoint server 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criteria operator="OR" comment="either files versions">
            <criterion comment="Check if the version of microsoft.office.server.native.dll is less than 14.0.7005.1000" test_ref="oval:org.mitre.oval:tst:87074"/>
            <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
            <criterion comment="Check if the version of xlsrv.dll is less than 14.0.7104.5000 (sharepoint server)" test_ref="oval:org.mitre.oval:tst:86965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="foundation 2013/version">
          <criterion comment="Check if the version of Microsoft.office.server.native.dll is less than 15.0.4535.1000" test_ref="oval:org.mitre.oval:tst:87023"/>
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2013/version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of Onfda.dll is less than 15.0.4535.1000" test_ref="oval:org.mitre.oval:tst:86497"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19090" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2013"/>
        <description>Microsoft SharePoint Foundation 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T13:16:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:15.530-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:44.863-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:25.849-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft SharePoint Foundation 2013 is installed" test_ref="oval:org.mitre.oval:tst:87180"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19047" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010:sp2"/>
        <description>Microsoft SharePoint Foundation 2010 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:10.996-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:34.923-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:24.234-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if Microsoft SharePoint Foundation 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:87020"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19100" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3849) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3849"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:29.586-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:48.195-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:26.489-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18988" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3847) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3847"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3848, CVE-2013-3849, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:26.744-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:17.125-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:20.571-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18942" version="3" class="vulnerability">
      <metadata>
        <title>Word memory corruption vulnerability in Microsoft SharePoint (CVE-2013-3857) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3857"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1 and SP2, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:36.867-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:04.763-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:18.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <criteria operator="OR" comment="sharepoint server 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <criteria operator="OR" comment="office web apps sp1/sp2">
            <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
            <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19186"/>
          </criteria>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19186" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010:sp2"/>
        <description>Microsoft Office Web Apps 2010 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:16.599-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26572 - '\' precedding '_' removed in object regex;un-deprecated registry state" date="2013-11-08T09:48:00.143-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-26T13:49:28.297-05:00">INTERIM</status_change>
            <status_change date="2013-12-16T04:01:31.088-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26572 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:47.701-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:07.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
        <criterion comment="Check if Microsoft Office Web Apps 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:86576"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18921" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2010:sp2"/>
        <description>Microsoft SharePoint Server 2010 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:12.179-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:58.881-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:16.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:23979 - ms14-001, new registry tst to detect SP's properly, def:18921 15614 updated to check display version" date="2014-01-21T16:50:00.071-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-21T17:03:44.673-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:10.747-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
        <criterion comment="Check if Microsoft SharePoint 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:86608"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18801" version="3" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft SharePoint (CVE-2013-3858) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3858"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3849.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:19.228-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:36.426-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:11.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18800" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3848) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3848"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3849, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:39.934-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:35.846-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:11.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15860" version="7" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010:sp1"/>
        <description>Microsoft Office Web Apps 2010 Service Pack 1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T09:07:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:11:26.152-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:23.370-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:14.164-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24131 - Symbol \ (backslash) is not needed because symbol _ (underscore) isn't a metacharacter." date="2013-08-29T09:21:00.244-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-29T09:22:52.391-04:00">INTERIM</status_change>
            <status_change date="2013-09-16T04:00:21.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24131 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.693-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:26.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Office Web Apps SP1 is installed" test_ref="oval:org.mitre.oval:tst:80139"/>
        <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15787" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010"/>
        <description>Microsoft Office Web Apps 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T14:16:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:11:25.935-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:19.815-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:13.143-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Web Apps is installed" test_ref="oval:org.mitre.oval:tst:80134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18376" version="4" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities - CVE-2013-2393 (MS13-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-2393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2393"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:51:17">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:41:13.943-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18376 - Revised MS13-061 to V3.0" date="2013-09-04T14:47:00.917-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2013-09-23T04:05:37.920-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:16.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.3.327.1" test_ref="oval:org.mitre.oval:tst:85968"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.2.375.0" test_ref="oval:org.mitre.oval:tst:85977"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP3 is installed" definition_ref="oval:org.mitre.oval:def:17932"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.3.158.1" test_ref="oval:org.mitre.oval:tst:85918"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU1 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 1 is installed" definition_ref="oval:org.mitre.oval:def:18838"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.0.620.34" test_ref="oval:org.mitre.oval:tst:86148"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 2 is installed" definition_ref="oval:org.mitre.oval:def:18484"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.0.712.28" test_ref="oval:org.mitre.oval:tst:86102"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18243" version="4" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities - CVE-2013-3776 (MS13-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3776"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7, 8.4.0, and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-3781.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:51:17">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:41:09.968-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18243 - Revised MS13-061 to V3.0" date="2013-09-04T14:47:00.917-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2013-09-23T04:05:19.277-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:12.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.3.327.1" test_ref="oval:org.mitre.oval:tst:85968"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.2.375.0" test_ref="oval:org.mitre.oval:tst:85977"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP3 is installed" definition_ref="oval:org.mitre.oval:def:17932"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.3.158.1" test_ref="oval:org.mitre.oval:tst:85918"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU1 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 1 is installed" definition_ref="oval:org.mitre.oval:def:18838"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.0.620.34" test_ref="oval:org.mitre.oval:tst:86148"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 2 is installed" definition_ref="oval:org.mitre.oval:def:18484"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.0.712.28" test_ref="oval:org.mitre.oval:tst:86102"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18156" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities - CVE-2013-3781 (MS13-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3781"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7, 8.4.0, and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-3776.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:51:17">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:41:12.106-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18156 - Revised MS13-061 to V3.0" date="2013-09-04T14:47:00.917-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2013-09-23T04:05:00.454-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:11.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.3.327.1" test_ref="oval:org.mitre.oval:tst:85968"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.2.375.0" test_ref="oval:org.mitre.oval:tst:85977"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP3 is installed" definition_ref="oval:org.mitre.oval:def:17932"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.3.158.1" test_ref="oval:org.mitre.oval:tst:85918"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 CU1 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 1 is installed" definition_ref="oval:org.mitre.oval:def:18838"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.0.620.34" test_ref="oval:org.mitre.oval:tst:86148"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU2 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 Cumulative Update 2 is installed" definition_ref="oval:org.mitre.oval:def:18484"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.0.712.28" test_ref="oval:org.mitre.oval:tst:86102"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18838" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu1"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-03T10:20:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-04T14:49:16.638-04:00">DRAFT</status_change>
            <status_change date="2013-09-23T04:05:38.966-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:26.348-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 is installed Cumulative Update 1" test_ref="oval:org.mitre.oval:tst:86178"/>
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18484" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 Cumulative Update 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu2"/>
        <description>Microsoft Exchange Server 2013 Cumulative Update 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-03T10:20:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-04T14:49:15.758-04:00">DRAFT</status_change>
            <status_change date="2013-09-23T04:05:38.557-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:17.243-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 is installed Cumulative Update 2" test_ref="oval:org.mitre.oval:tst:86716"/>
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18626" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013"/>
        <description>Microsoft Exchange Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-03T10:20:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-04T14:49:15.323-04:00">DRAFT</status_change>
            <status_change date="2013-09-23T04:05:38.765-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:17.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:86283"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17932" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010:sp3"/>
        <description>Microsoft Exchange Server 2010 SP3 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:51:17">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:41:09.817-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:03.757-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:44.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
        <criterion comment="Check if Microsoft Exchange Server 2010 SP3 is installed" test_ref="oval:org.mitre.oval:tst:85809"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16925" version="4" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Management Pack for Oracle GoldenGate Server. Supported versions that are affected are 11.1.1.1.0.
		Vulnerability in the Oracle GoldenGate Veridata component of Oracle Fusion Middleware (subcomponent: Server). The supported version that is affected is 3.0.0.11.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Veridata</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Oracle GoldenGate Director</product>
          <product>Oracle GoldenGate Veridata</product>
        </affected>
        <reference ref_id="CVE-2012-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" source="CVE"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-29T10:26:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-06-19T16:06:43.613-04:00">DRAFT</status_change>
            <status_change date="2013-07-08T04:02:15.887-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:00:59.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if version of Oracle GoldenGate Director is 11.1.1.1.0" test_ref="oval:org.mitre.oval:tst:81231"/>
        <criterion comment="Check if version for Oracle GoldenGate Veridata is 3.0.0.11.0" test_ref="oval:org.mitre.oval:tst:80940"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16596" version="5" class="vulnerability">
      <metadata>
        <title>Callback Function Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0080"/>
        <description>Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.096-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:41.275-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:19.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.752-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:13.034-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" test_ref="oval:org.mitre.oval:tst:80956"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16500" version="3" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerability - CVE-2012-3214 (MS13-013)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3214"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T14:21:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T17:20:32.699-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:19.853-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:01:01.579-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
        <criterion comment="Check if the version of vseshr.dll is less than 8.3.7.207" test_ref="oval:org.mitre.oval:tst:80570"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16445" version="5" class="vulnerability">
      <metadata>
        <title>SharePoint Directory Traversal Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0084"/>
        <description>Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.326-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:29.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:05.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.054-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:12.814-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" test_ref="oval:org.mitre.oval:tst:80956"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16414" version="5" class="vulnerability">
      <metadata>
        <title>Buffer Overflow Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0085"/>
        <description>Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.572-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:28.554-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:02.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:48.452-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:12.526-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" test_ref="oval:org.mitre.oval:tst:80956"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16251" version="4" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft Exchange Server Could Allow Remote Code Execution - CVE-2013-0418 - MS13-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0418"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393.  NOTE: the previous information was obtained from the January 2013 CPU.  Oracle has not commented on claims from an independent researcher that this is a heap-based buffer overflow in the Paradox database stream filter (vspdx.dll) that can be triggered using a table header with a crafted "number of fields" value.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T15:20:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T17:18:22.885-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:00:32.728-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:20.513-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="exchange server 2007/version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version ExSetup.exe is less than 8.3.298.3" test_ref="oval:org.mitre.oval:tst:80872"/>
        </criteria>
        <criteria operator="AND" comment="exchange server 2010/version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15546"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.2.342.2" test_ref="oval:org.mitre.oval:tst:80598"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16232" version="3" class="vulnerability">
      <metadata>
        <title>System Center Operations Manager Web Console XSS Vulnerability-II - MS13-003</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft System Center Operations Manager 2007</product>
          <product>Microsoft System Center Operations Manager 2007 R2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0010"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-01-10T16:59:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-01-10T11:18:30.675-05:00">DRAFT</status_change>
            <status_change date="2013-01-28T04:00:59.968-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:12.125-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="SCOM 2007 is installed and vuln file">
          <extend_definition comment="Microsoft System Center Operations Manager 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:16286"/>
          <criterion comment="Check if the version of AuditingMessages.dll is less than or equal to 6.0.6278.0" test_ref="oval:org.mitre.oval:tst:80576"/>
        </criteria>
        <criteria operator="AND" comment="2007 R2 and vulnerable file version">
          <extend_definition comment="Microsoft System Center Operations Manager 2007 R2 is installed" definition_ref="oval:org.mitre.oval:def:16190"/>
          <criterion comment="Check if the version of AuditingMessages.dll is less than 6.1.7221.110" test_ref="oval:org.mitre.oval:tst:80122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16204" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Essentials Could Allow Information Disclosure - MS13-045</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Windows Essentials 2012</product>
          <product>Microsoft Windows Essentials 2011</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0096"/>
        <description>Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T10:14:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:45:56.932-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:00:44.203-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:30.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Windows Essentials 2011 is installed" definition_ref="oval:org.mitre.oval:def:16645"/>
        <criteria operator="AND" comment="windows essentials 2012/version">
          <extend_definition comment="Microsoft Windows Essentials 2012 is installed" definition_ref="oval:org.mitre.oval:def:16746"/>
          <criterion comment="Check if the version of Windowslivewriter.exe is less than 16.4.3508.205" test_ref="oval:org.mitre.oval:tst:81120"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16746" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Essentials 2012 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Windows Essentials 2012</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_essentials:2012"/>
        <description>Microsoft Windows Essentials 2012 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T11:11:38">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:45:56.629-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:33.268-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:01:11.784-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Windows Essentials is installed" test_ref="oval:org.mitre.oval:tst:80220"/>
        <criterion comment="Check if Windows Essentials 2012 is installed" test_ref="oval:org.mitre.oval:tst:80229"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16645" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Essentials 2011 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Windows Essentials 2011</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_essentials:2011"/>
        <description>Microsoft Windows Essentials 2011 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T11:11:38">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:45:56.349-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:21.825-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:56.481-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Windows Essentials is installed" test_ref="oval:org.mitre.oval:tst:80220"/>
        <criterion comment="Check if Windows Essentials 2011 is installed" test_ref="oval:org.mitre.oval:tst:80928"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16202" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft Exchange Server Could Allow Remote Code Execution - CVE-2013-0393 - MS13-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0393"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0418.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T15:20:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T17:18:22.674-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:00:24.360-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:16.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="exchange server 2007/version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version ExSetup.exe is less than 8.3.298.3" test_ref="oval:org.mitre.oval:tst:80872"/>
        </criteria>
        <criteria operator="AND" comment="exchange server 2010/version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15546"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.2.342.2" test_ref="oval:org.mitre.oval:tst:80598"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15546" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010:sp2"/>
        <description>Microsoft Exchange Server 2010 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-04-04T12:52:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2012-04-06T11:34:21.189-04:00">DRAFT</status_change>
            <status_change date="2012-04-23T04:00:23.864-04:00">INTERIM</status_change>
            <status_change date="2012-05-14T04:00:16.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
        <criterion comment="Microsoft Exchange Server 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:78176"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16178" version="3" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities-I MS12-080</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3214"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-12-12T08:43:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-12-12T19:43:58.718-05:00">DRAFT</status_change>
            <status_change date="2012-12-31T04:02:03.099-05:00">INTERIM</status_change>
            <status_change date="2013-01-21T04:00:39.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version ExSetup.exe is less than 8.3.297.2" test_ref="oval:org.mitre.oval:tst:79624"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.1.438.0" test_ref="oval:org.mitre.oval:tst:80439"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.2.328.10" test_ref="oval:org.mitre.oval:tst:80396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16158" version="3" class="vulnerability">
      <metadata>
        <title>RSS Feed May Cause Exchange DoS Vulnerability - MS12-080</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-4791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4791"/>
        <description>Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-12-12T08:43:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-12-12T19:43:58.501-05:00">DRAFT</status_change>
            <status_change date="2012-12-31T04:02:00.481-05:00">INTERIM</status_change>
            <status_change date="2013-01-21T04:00:36.888-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version ExSetup.exe is less than 8.3.297.2" test_ref="oval:org.mitre.oval:tst:79624"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.1.438.0" test_ref="oval:org.mitre.oval:tst:80439"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.2.328.10" test_ref="oval:org.mitre.oval:tst:80396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16080" version="3" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerability - CVE-2012-3217 (MS13-013)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3217"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability, related to Outside In HTML Export SDK.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T14:21:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T17:20:32.833-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:00:16.301-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:11.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
        <criterion comment="Check if the version of vseshr.dll is less than 8.3.7.207" test_ref="oval:org.mitre.oval:tst:80570"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15911" version="3" class="vulnerability">
      <metadata>
        <title>Oracle Outside In Contains Multiple Exploitable Vulnerabilities-II MS12-080</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3217"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability, related to Outside In HTML Export SDK.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-12-12T08:43:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-12-12T19:43:58.935-05:00">DRAFT</status_change>
            <status_change date="2012-12-31T04:01:39.108-05:00">INTERIM</status_change>
            <status_change date="2013-01-21T04:00:19.244-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version ExSetup.exe is less than 8.3.297.2" test_ref="oval:org.mitre.oval:tst:79624"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.1.438.0" test_ref="oval:org.mitre.oval:tst:80439"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version ExSetup.exe is less than 14.2.328.10" test_ref="oval:org.mitre.oval:tst:80396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15812" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - II</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1767"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:06.929-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:37.642-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:34.081-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:03.763-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:20.939-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15804" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - XI</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3108"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:09.211-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:36.501-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:32.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15804 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:38:58.775-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:20.227-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15781" version="5" class="vulnerability">
      <metadata>
        <title>Reflected XSS Vulnerability - MS12-062</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft System Center Configuration Manager 2007</product>
          <product>Microsoft System Center Configuration Manager 2007 R2</product>
          <product>Microsoft System Center Configuration Manager 2007 R3</product>
          <product>Microsoft Systems Management Server 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-2536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2536"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T09:31:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:30.646-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:30.570-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:44.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:80096 - Updates based on revised bulletin for MS12-062." date="2012-11-19T16:12:00.903-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-11-19T16:20:34.844-05:00">INTERIM</status_change>
            <status_change date="2012-12-10T04:00:13.311-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable SMS 2003/file version">
          <extend_definition comment="Microsoft Systems Management Server 2003 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15150"/>
          <criterion comment="Check if version of ReportingInstall.exe (SMS 2003) is less than 2.50.4253.3129" test_ref="oval:org.mitre.oval:tst:80064"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SCCM 2007/file version">
          <criterion comment="Check if version of ReportingInstall.exe (SCCM 2007) is less than 4.0.6487.2216" test_ref="oval:org.mitre.oval:tst:80096"/>
          <criteria operator="OR" comment="Either applications">
            <extend_definition comment="Microsoft System Center Configuration Manager 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15636"/>
            <extend_definition comment="Microsoft System Center Configuration Manager 2007 R2 is installed" definition_ref="oval:org.mitre.oval:def:15840"/>
            <extend_definition comment="Microsoft System Center Configuration Manager 2007 R3 is installed" definition_ref="oval:org.mitre.oval:def:15833"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15840" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 R2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft System Center Configuration Manager 2007 R2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007:r2"/>
        <description>Microsoft System Center Configuration Manager 2007 R2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T09:31:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:30.145-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:35.776-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:46.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 R2 is installed" test_ref="oval:org.mitre.oval:tst:80002"/>
        <extend_definition comment="Microsoft System Center Configuration Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:15678"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15833" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 R3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft System Center Configuration Manager 2007 R3</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007:r3"/>
        <description>Microsoft System Center Configuration Manager 2007 R3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T09:31:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:30.433-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:35.255-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:46.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 R3 is installed" test_ref="oval:org.mitre.oval:tst:79954"/>
        <extend_definition comment="Microsoft System Center Configuration Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:15678"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15636" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft System Center Configuration Manager 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007:sp2"/>
        <description>Microsoft System Center Configuration Manager 2007 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:29.178-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:17.770-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:35.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft System Center Configuration Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:15678"/>
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 SP2 is installed" test_ref="oval:org.mitre.oval:tst:80097"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15678" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft System Center Configuration Manager 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007"/>
        <description>Microsoft System Center Configuration Manager 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:28.852-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:21.696-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:37.946-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 is installed" test_ref="oval:org.mitre.oval:tst:80024"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15150" version="3" class="inventory">
      <metadata>
        <title>Microsoft Systems Management Server 2003 SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Systems Management Server 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2003:sp3"/>
        <description>Microsoft Systems Management Server 2003 SP3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:29.676-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:07.264-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:06.888-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Systems Management Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:15121"/>
        <criterion comment="Check if Microsoft Systems Management Server 2003 SP3 is installed" test_ref="oval:org.mitre.oval:tst:79365"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15121" version="3" class="inventory">
      <metadata>
        <title>Microsoft Systems Management Server 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Systems Management Server 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2003"/>
        <description>Microsoft Systems Management Server 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:29.443-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:06.995-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:05.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Systems Management Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:80078"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15779" version="5" class="vulnerability">
      <metadata>
        <title>XSS Vulnerability - MS12-061</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Visual Studio Team Foundation Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1892"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:42:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:41:55.325-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:30.276-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:43.861-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1065 - Added &quot;\&quot; symbol before every &quot;.&quot; symbol." date="2014-07-25T11:52:00.286-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-25T11:54:00.659-04:00">INTERIM</status_change>
            <status_change date="2014-08-11T04:00:12.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Visual Studio Team Foundation Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15187"/>
        <criterion comment="Check if the version of Microsoft.TeamFoundation.WebAccess.dll is less than 10.0.40219.417" test_ref="oval:org.mitre.oval:tst:79715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15187" version="3" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio Team Foundation Server 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Visual Studio Team Foundation Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_team_foundation_server:2010:sp1"/>
        <description>Microsoft Visual Studio Team Foundation Server 2010 Service Pack 1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:42:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:41:54.467-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:07.859-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:08.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Visual Studio Team Foundation Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:15512"/>
        <criterion comment="Check if Visual Studio Team Foundation Server 2010 SP1 is installed" test_ref="oval:org.mitre.oval:tst:79804"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15512" version="3" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio Team Foundation Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Visual Studio Team Foundation Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_team_foundation_server:2010"/>
        <description>Microsoft Visual Studio Team Foundation Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:42:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:41:53.623-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:12.698-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:25.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Visual Studio Team Foundation Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:80166"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15760" version="3" class="vulnerability">
      <metadata>
        <title>System Center Operations Manager Web Console XSS Vulnerability-I - MS13-003</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft System Center Operations Manager 2007</product>
          <product>Microsoft System Center Operations Manager 2007 R2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0009"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-01-10T16:59:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-01-10T11:18:30.481-05:00">DRAFT</status_change>
            <status_change date="2013-01-28T04:00:58.210-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:09.934-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="SCOM 2007 is installed and vuln file">
          <extend_definition comment="Microsoft System Center Operations Manager 2007 SP1 is installed" definition_ref="oval:org.mitre.oval:def:16286"/>
          <criterion comment="Check if the version of AuditingMessages.dll is less than or equal to 6.0.6278.0" test_ref="oval:org.mitre.oval:tst:80576"/>
        </criteria>
        <criteria operator="AND" comment="2007 R2 and vulnerable file version">
          <extend_definition comment="Microsoft System Center Operations Manager 2007 R2 is installed" definition_ref="oval:org.mitre.oval:def:16190"/>
          <criterion comment="Check if the version of AuditingMessages.dll is less than 6.1.7221.110" test_ref="oval:org.mitre.oval:tst:80122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16286" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Operations Manager 2007 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft System Center Operations Manager 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:system_center_operations_manager:2007:sp1"/>
        <description>Microsoft System Center Operations Manager 2007 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-01-10T16:59:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-01-10T11:18:29.856-05:00">DRAFT</status_change>
            <status_change date="2013-01-28T04:01:01.380-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:13.488-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft System Center Operations Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:16114"/>
        <criterion comment="Check if the version of Microsoft System Center Operations Manager 2007 is greater than or equal to 6.0.6278.0" test_ref="oval:org.mitre.oval:tst:80567"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16114" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Operations Manager 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft System Center Operations Manager 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:system_center_operations_manager:2007"/>
        <description>Microsoft System Center Operations Manager 2007 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-01-10T16:59:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-01-10T11:18:29.640-05:00">DRAFT</status_change>
            <status_change date="2013-01-28T04:00:59.476-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:11.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Operations Manager 2007 is installed" test_ref="oval:org.mitre.oval:tst:80596"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16190" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Operations Manager 2007 R2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft System Center Operations Manager 2007 R2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:system_center_operations_manager:2007:r2"/>
        <description>Microsoft System Center Operations Manager 2007 R2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-01-10T16:59:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-01-10T11:18:30.157-05:00">DRAFT</status_change>
            <status_change date="2013-01-28T04:00:59.738-05:00">INTERIM</status_change>
            <status_change date="2013-02-18T04:00:11.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Operations Manager 2007 R2 is installed" test_ref="oval:org.mitre.oval:tst:80638"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15758" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in SharePoint could allow information disclosure - MS13-030</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1290"/>
        <description>Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T10:24:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:05:35.219-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:01:41.010-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:05.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
        <criterion comment="Check if the version of Microsoft.office.server.dll is less than 15.0.4481.1507" test_ref="oval:org.mitre.oval:tst:81077"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16325" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2013"/>
        <description>Microsoft SharePoint Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T10:24:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:05:34.844-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:05.965-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:08.177-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if SharePoint Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:80504"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15747" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - XIII</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3110"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:09.655-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:33.715-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:29.186-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:07.568-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:18.553-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15724" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - I</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1766"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:06.610-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:31.458-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:25.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:07.223-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:15.227-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15721" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - IV</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1769"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:07.410-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:31.140-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:25.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:06.688-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:14.432-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15668" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - VI</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1771"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:07.854-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:27.438-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:19.288-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:05.609-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:12.027-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15667" version="5" class="vulnerability">
      <metadata>
        <title>TrueType Font Parsing Vulnerability (CVE-2012-0159)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010</product>
          <product>Microsoft Lync 2010 Attendee</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0159"/>
        <description>Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T15:13:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:11.640-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:32.648-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:35.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23843 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:39.185-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:22.478-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable lync 2010">
          <extend_definition comment="Microsoft Lync 2010 is installed" definition_ref="oval:org.mitre.oval:def:15099"/>
          <criterion comment="Check if version of Communicator.exe (Lync 2010) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79972"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendee (admin)">
          <extend_definition comment="Microsoft Lync 2010 Attendee (user level install) is installed" definition_ref="oval:org.mitre.oval:def:15641"/>
          <criterion comment="Check if version of ogl.dll (Lync 2010 Attendee for admin) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79522"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendee (user)">
          <extend_definition comment="Microsoft Lync 2010 Attendee (admin level install) is installed" definition_ref="oval:org.mitre.oval:def:15556"/>
          <criterion comment="Check if version of ogl.dll (Lync 2010 Attendee for user) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79686"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15648" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - X</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3107"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:08.808-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:26.871-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:18.282-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:03.414-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:11.145-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15608" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - IX</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3106"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:08.587-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:26.236-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:16.648-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:04.504-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:10.367-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15589" version="5" class="vulnerability">
      <metadata>
        <title>XSS scriptresx.ashx Vulnerability - MS12-050</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1859" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1859"/>
        <description>Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:14.134-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:12.193-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:28.676-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.494-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:11.970-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010">
          <criterion comment="Check if the version of Microsoft.office.server.native.dll is less than 14.0.6108.5000" test_ref="oval:org.mitre.oval:tst:79844"/>
          <criteria operator="OR" comment="shrepoint server 2010/sp1">
            <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2010">
          <criterion comment="Check if the version of Onfda.dll is less than 14.0.6106.5000" test_ref="oval:org.mitre.oval:tst:79803"/>
          <criteria operator="OR" comment="sharepoint foundation 2010/sp1">
            <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15568" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - VIII</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1773"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:08.358-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:25.341-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:14.915-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:04.156-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:09.667-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15544" version="6" class="vulnerability">
      <metadata>
        <title>SharePoint Script in Username Vulnerability - MS12-050</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1861" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1861"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:14.785-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:11.853-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:27.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:47.728-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:11.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010">
          <criterion comment="Check if the version of Microsoft.office.server.native.dll is less than 14.0.6108.5000" test_ref="oval:org.mitre.oval:tst:79844"/>
          <criteria operator="OR" comment="sharepoint server 2010/sp1">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2010">
          <criterion comment="Check if the version of Onfda.dll is less than 14.0.6106.5000" test_ref="oval:org.mitre.oval:tst:79803"/>
          <criteria operator="OR" comment="sharepoint foundation 2010/sp1">
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15661" version="7" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
        <description>Microsoft SharePoint Foundation 2010 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:12.759-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:14.532-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:33.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15661 - Microsoft Bulletins: MS13-024 and MS13-025 (March 2013)" date="2013-03-18T14:50:00.119-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-03-18T14:53:12.547-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:12.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24020 - Symbol \ (backslash) is not needed because symbol _ (underscore) isn't a metacharacter." date="2013-08-29T09:21:00.244-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-29T09:22:48.716-04:00">INTERIM</status_change>
            <status_change date="2013-09-16T04:00:21.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:79390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15614" version="7" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <description>Microsoft SharePoint Server 2010 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:13.329-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:12.930-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:29.799-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24062 - corrected regex (symbol '\' not needed before symbol '_')" date="2013-09-06T14:20:00.865-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-06T14:21:25.926-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:00:08.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19908 - ms14-001, new registry tst to detect SP's properly, def:18921 15614 updated to check display version" date="2014-01-21T16:50:00.071-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-21T17:03:44.381-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:06.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
        <criterion comment="Check if Microsoft SharePoint Server 2010 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:80093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15323" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - VII</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1772"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:08.136-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:19.422-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:10.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:06.336-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:07.023-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15290" version="5" class="vulnerability">
      <metadata>
        <title>TrueType Font Parsing Vulnerability (CVE-2011-3402)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010</product>
          <product>Microsoft Lync 2010 Attendee</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-3402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3402"/>
        <description>Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T15:13:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:11.377-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:13.948-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:17.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23843 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:39.239-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:12.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable lync 2010">
          <extend_definition comment="Microsoft Lync 2010 is installed" definition_ref="oval:org.mitre.oval:def:15099"/>
          <criterion comment="Check if version of Communicator.exe (Lync 2010) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79972"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendee (admin)">
          <extend_definition comment="Microsoft Lync 2010 Attendee (user level install) is installed" definition_ref="oval:org.mitre.oval:def:15641"/>
          <criterion comment="Check if version of ogl.dll (Lync 2010 Attendee for admin) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79522"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendee (user)">
          <extend_definition comment="Microsoft Lync 2010 Attendee (admin level install) is installed" definition_ref="oval:org.mitre.oval:def:15556"/>
          <criterion comment="Check if version of ogl.dll (Lync 2010 Attendee for user) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79686"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15275" version="6" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - III</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1768" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1768"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:07.187-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:18.597-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:09.738-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:05.951-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:06.582-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14882" version="5" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - V</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1770"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:07.632-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:09.543-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:05.498-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:05.266-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:04.838-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14874" version="5" class="vulnerability">
      <metadata>
        <title>Lync Insecure Library Loading Vulnerability (CVE-2012-1849)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010</product>
          <product>Microsoft Lync 2010 Attendant</product>
          <product>Microsoft Lync 2010 Attendee</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1849"/>
        <description>Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T15:13:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:11.993-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:07.855-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:11.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23843 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:38.326-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:09.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable lync 2010">
          <extend_definition comment="Microsoft Lync 2010 is installed" definition_ref="oval:org.mitre.oval:def:15099"/>
          <criterion comment="Check if version of Communicator.exe (Lync 2010) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79972"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendee (admin)">
          <extend_definition comment="Microsoft Lync 2010 Attendee (user level install) is installed" definition_ref="oval:org.mitre.oval:def:15641"/>
          <criterion comment="Check if version of ogl.dll (Lync 2010 Attendee for admin) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79522"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendee (user)">
          <extend_definition comment="Microsoft Lync 2010 Attendee (admin level install) is installed" definition_ref="oval:org.mitre.oval:def:15556"/>
          <criterion comment="Check if version of ogl.dll (Lync 2010 Attendee for user) is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:79686"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable lync 2010 attendant">
          <extend_definition comment="Microsoft Lync 2010 Attendant is installed" definition_ref="oval:org.mitre.oval:def:15600"/>
          <criterion comment="Check if version of Attendantconsole.exe is less than 4.0.7577.4098" test_ref="oval:org.mitre.oval:tst:80016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15641" version="5" class="inventory">
      <metadata>
        <title>Microsoft Lync 2010 Attendee (user level install) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010 Attendee</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_attendee:2010:user_level"/>
        <description>Microsoft Lync 2010 Attendee (user level install) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T12:17:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:00.354-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:30.916-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:31.701-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23843 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:39.291-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:21.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync 2010 Attendee (user level install) is installed" test_ref="oval:org.mitre.oval:tst:79595"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15600" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync 2010 Attendant is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010 Attendant</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_attendant:2010"/>
        <description>Microsoft Lync 2010 Attendant is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T12:17:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:11.139-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:28.478-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:28.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync 2010 Attendant is installed" test_ref="oval:org.mitre.oval:tst:79186"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15556" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync 2010 Attendee (admin level install) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010 Attendee</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_attendee:2010:admin_level"/>
        <description>Microsoft Lync 2010 Attendee (admin level install) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T12:17:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:00.736-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:25.415-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:25.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync 2010 Attendee (admin level install) is installed" test_ref="oval:org.mitre.oval:tst:79499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15099" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Lync 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync:2010"/>
        <description>Microsoft Lync 2010 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-06-18T12:17:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:05:00.126-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:12.234-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:16.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync 2010 is installed" test_ref="oval:org.mitre.oval:tst:79642"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14834" version="6" class="vulnerability">
      <metadata>
        <title>Oracle Outside In contains multiple exploitable vulnerabilities - XII</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3109"/>
        <description>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-20T10:24:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:09.434-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:08.592-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:04.092-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19493 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.069-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:39:04.876-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:04.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2007 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15784"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" test_ref="oval:org.mitre.oval:tst:80087"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP1 vulnerable version">
          <extend_definition comment="Microsoft Exchange Server 2010 SP1 is installed" definition_ref="oval:org.mitre.oval:def:15339"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" test_ref="oval:org.mitre.oval:tst:80199"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 SP2">
          <extend_definition comment="Microsoft Exchange Server 2010 SP2 is installed" definition_ref="oval:org.mitre.oval:def:14151"/>
          <criterion comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" test_ref="oval:org.mitre.oval:tst:79908"/>
        </criteria>
        <criteria operator="AND" comment="FAST Search Server 2010 for SharePoint vulnerable version">
          <extend_definition comment="Microsoft FAST Search Server 2010 for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:15918"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" test_ref="oval:org.mitre.oval:tst:80085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15918" version="3" class="inventory">
      <metadata>
        <title>Microsoft FAST Search Server 2010 for SharePoint is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft FAST Search Server 2010 for SharePoint</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:fast_search_server_for_sharepoint:2010"/>
        <description>Microsoft FAST Search Server 2010 for SharePoint is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T11:11:47">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:37:56.218-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:25.264-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:17.344-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if FAST Search Server 2010 for SharePoint is installed" test_ref="oval:org.mitre.oval:tst:79536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15784" version="7" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2007 SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2007:sp3"/>
        <description>Microsoft Exchange Server 2007 SP3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-08-09T05:34:23">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-08-20T16:06:05.785-04:00">DRAFT</status_change>
            <status_change date="2012-09-10T04:00:34.873-04:00">INTERIM</status_change>
            <status_change date="2012-10-01T04:00:30.928-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15784 - The attached file contains new inventories and vulnerabilities for Oracle products." date="2013-06-19T16:04:00.140-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-06-19T16:24:10.413-04:00">INTERIM</status_change>
            <status_change date="2013-07-08T04:01:27.811-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:80116 - Microsoft bulletin for the month of August 2013 MS13-061" date="2013-08-19T14:39:00.335-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-08-19T14:41:15.490-04:00">INTERIM</status_change>
            <status_change date="2013-09-09T04:00:07.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Exchange Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:8521"/>
        <criterion comment="Check if Exchange Server 2007 SP3 is installed" test_ref="oval:org.mitre.oval:tst:80116"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15339" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010:sp1"/>
        <description>Microsoft Exchange Server 2010 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-04-04T12:52:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2012-04-06T11:34:18.828-04:00">DRAFT</status_change>
            <status_change date="2012-04-23T04:00:17.466-04:00">INTERIM</status_change>
            <status_change date="2012-05-14T04:00:10.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
        <criterion comment="Microsoft Exchange Server 2010 SP1 is installed" test_ref="oval:org.mitre.oval:tst:78247"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14151" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010:sp2"/>
        <description>Microsoft Exchange Server 2010 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-03-27T12:52:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2012-03-27T14:18:30.473-04:00">DRAFT</status_change>
            <status_change date="2012-04-16T04:02:22.437-04:00">INTERIM</status_change>
            <status_change date="2012-05-07T04:00:04.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
        <criterion comment="Microsoft Exchange Server 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:78176"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14826" version="3" class="vulnerability">
      <metadata>
        <title>XSS in wizardlist.aspx Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0145" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0145"/>
        <description>Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-02-14T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2012-02-21T12:28:22.834-05:00">DRAFT</status_change>
            <status_change date="2012-03-12T04:00:29.462-04:00">INTERIM</status_change>
            <status_change date="2012-04-02T04:00:22.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6113.5000" test_ref="oval:org.mitre.oval:tst:78074"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6114.5001" test_ref="oval:org.mitre.oval:tst:77961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14637" version="3" class="vulnerability">
      <metadata>
        <title>XSS in inplview.aspx Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0017" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0017"/>
        <description>Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-02-14T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2012-02-21T12:28:22.209-05:00">DRAFT</status_change>
            <status_change date="2012-03-12T04:00:21.224-04:00">INTERIM</status_change>
            <status_change date="2012-04-02T04:00:15.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="OWSSVR.DLL version is less than 14.0.6114.5001" test_ref="oval:org.mitre.oval:tst:77961"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14386" version="3" class="vulnerability">
      <metadata>
        <title>XSS in themeweb.aspx Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0144" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0144"/>
        <description>Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-02-14T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2012-02-21T12:28:23.117-05:00">DRAFT</status_change>
            <status_change date="2012-03-12T04:00:16.211-04:00">INTERIM</status_change>
            <status_change date="2012-04-02T04:00:09.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6113.5000" test_ref="oval:org.mitre.oval:tst:78074"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6114.5001" test_ref="oval:org.mitre.oval:tst:77961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14314" version="5" class="vulnerability">
      <metadata>
        <title>AntiXSS Library Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Anti-Cross Site Scripting Library V3.x</product>
          <product>Microsoft Anti-Cross Site Scripting Library V4.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0007"/>
        <description>The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-01-10T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2012-01-13T18:25:32.666-05:00">DRAFT</status_change>
            <status_change date="2012-01-30T04:00:30.169-05:00">INTERIM</status_change>
            <status_change date="2012-02-20T04:00:04.880-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1436 - vulnerabilities for VMware and inventories for VMware Workstation, VMware View and VMware Player." date="2013-06-21T12:00:00.019-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-21T12:13:31.428-04:00">INTERIM</status_change>
            <status_change date="2013-07-08T04:01:10.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Anti-Cross Site Scripting Library 3.x or 4.0 is installed" test_ref="oval:org.mitre.oval:tst:77867"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12864" version="5" class="vulnerability">
      <metadata>
        <title>Contact Details Reflected XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Windows SharePoint Services 3.0</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1891" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1891"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:29.926-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:33.744-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:58.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:37.786-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:00:06.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6565.5001" test_ref="oval:org.mitre.oval:tst:42957"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6106.5008" test_ref="oval:org.mitre.oval:tst:43889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12835" version="3" class="vulnerability">
      <metadata>
        <title>XSS in SharePoint Calendar Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0653" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0653"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:27.187-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:30.316-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:53.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrchwfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43686"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrv/wosrv)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.server.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43358"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmawfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Eawfap.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43900"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (dlc)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.policy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43892"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmamui)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Client.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43419"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6106.5008" test_ref="oval:org.mitre.oval:tst:43889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12788" version="3" class="vulnerability">
      <metadata>
        <title>Editform Script Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1890" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1890"/>
        <description>Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:29.615-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:26.156-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:48.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrchwfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43686"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrv/wosrv)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.server.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43358"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmawfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Eawfap.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43900"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (dlc)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.policy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43892"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmamui)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Client.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43419"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6106.5008" test_ref="oval:org.mitre.oval:tst:43889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12880" version="5" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2010 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint:2010"/>
        <description>Microsoft Office SharePoint Server 2010 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:26.061-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:35.882-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:00.596-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16204 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.822-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:30:25.998-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:03.694-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2010 is installed." test_ref="oval:org.mitre.oval:tst:43555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12224" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010"/>
        <description>Microsoft SharePoint Foundation 2010 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:26.985-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:07.602-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:15.672-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12224 - Microsoft Bulletins: MS13-024 and MS13-025 (March 2013)" date="2013-03-18T14:50:00.119-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-03-18T14:53:11.905-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:07.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Foundation 2010 is installed." test_ref="oval:org.mitre.oval:tst:43939"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <registry_test id="oval:org.mitre.oval:tst:4279" version="4" comment="SharePoint Server 2007 is installed." check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2686"/>
      <state state_ref="oval:org.mitre.oval:ste:3235"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:138630" version="1" comment="Check if the version of Microsoft.office.policy.dll is less than 14.0.7149.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15985"/>
      <state state_ref="oval:org.mitre.oval:ste:38541"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138608" version="2" comment="Check if the version of stswel.dll is less than 15.0.4719.1002" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:44015"/>
      <state state_ref="oval:org.mitre.oval:ste:38672"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138555" version="1" comment="Check if the version of onetutil.dll is less than 14.0.7149.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26888"/>
      <state state_ref="oval:org.mitre.oval:ste:38541"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:137831" version="1" comment="Check if the version of Microsoft.SharePoint.Portal.dll is less than 12.0.6721.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:43939"/>
      <state state_ref="oval:org.mitre.oval:ste:38210"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:138824" version="1" comment="Check if Exchange Server 2013 Cumulative Update 8 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:38813"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:139078" version="1" comment="Check if the version of Exsetup.exe is less than 15.0.847.41" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:39001"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:139030" version="1" comment="Check if the version of Exsetup.exe is less than 15.0.1076.011" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:38872"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:137998" version="1" comment="Check if the version of Microsoft.Office.Server.Search.dll is less than 15.0.4711.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:43159"/>
      <state state_ref="oval:org.mitre.oval:ste:38396"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:8498" version="1" comment="No Exchange Server 2007 SP is installed." check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6032"/>
      <state state_ref="oval:org.mitre.oval:ste:3489"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:135743" version="1" comment="Check if the version of ExSetup.exe is less than 14.03.0224.001" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:37587"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:135507" version="1" comment="Check if the version of exsetup.exe is less than 8.03.0389.002" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24081"/>
      <state state_ref="oval:org.mitre.oval:ste:37084"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:135802" version="1" comment="Microsoft Exchange Server Cumulative Update 6 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:37662"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:135793" version="1" comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:37067"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:135701" version="1" comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:36871"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:138458" version="1" comment="Check if Exchange Server 2013 Cumulative Update 7 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:38334"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:138401" version="1" comment="Check if the version of Exsetup.exe is less than 15.0.847.38" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:38372"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138053" version="1" comment="Check if the version of Exsetup.exe is less than 15.0.1044.29" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:38464"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138454" version="1" comment="Check if the version of onetutil.dll is less than 14.0.7145.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26888"/>
      <state state_ref="oval:org.mitre.oval:ste:38439"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138449" version="1" comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:43915"/>
      <state state_ref="oval:org.mitre.oval:ste:37582"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138441" version="1" comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:43884"/>
      <state state_ref="oval:org.mitre.oval:ste:38477"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138393" version="1" comment="Check if the version of vutils.dll is less than 15.0.4701.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:44052"/>
      <state state_ref="oval:org.mitre.oval:ste:38093"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138365" version="1" comment="Check if the version of msoserver.dll is less than 14.0.7145.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24128"/>
      <state state_ref="oval:org.mitre.oval:ste:38439"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138351" version="1" comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:29038"/>
      <state state_ref="oval:org.mitre.oval:ste:38421"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138339" version="1" comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:43614"/>
      <state state_ref="oval:org.mitre.oval:ste:38093"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138254" version="1" comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26773"/>
      <state state_ref="oval:org.mitre.oval:ste:38093"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138170" version="2" comment="Check if the version of stswel.dll is less than 15.0.4701.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:44015"/>
      <state state_ref="oval:org.mitre.oval:ste:38093"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:134500" version="2" comment="Check if the version of Onetutil.dll is less than 14.0.7137.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26888"/>
      <state state_ref="oval:org.mitre.oval:ste:37438"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:123329" version="1" comment="Check if the version of Deploy.resources.dll is less than 5.0.8308.420" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:41939"/>
      <state state_ref="oval:org.mitre.oval:ste:31615"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:123294" version="1" comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 5.0.8308.803" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:42109"/>
      <state state_ref="oval:org.mitre.oval:ste:33391"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:122801" version="1" comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 4.0.7577.276" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:42109"/>
      <state state_ref="oval:org.mitre.oval:ste:33946"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:123575" version="1" comment="Check if Microsoft Lync Server 2010 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24372"/>
      <state state_ref="oval:org.mitre.oval:ste:34174"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:81027" version="1" comment="Check if Microsoft Lync Server 2013 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24372"/>
      <state state_ref="oval:org.mitre.oval:ste:20728"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:123304" version="1" comment="Check if the version of wrtces.dll is less than 4.0.7577.230" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:42312"/>
      <state state_ref="oval:org.mitre.oval:ste:33474"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:123219" version="1" comment="Check if the version of SIPStack.dll is less than 5.0.8308.803" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:42322"/>
      <state state_ref="oval:org.mitre.oval:ste:33391"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:42359" version="3" comment="Internet Explorer 9 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:12091"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:121842" version="1" comment="Check if the version of wsssetup.dll is less than 15.0.4641.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:38235"/>
      <state state_ref="oval:org.mitre.oval:ste:33464"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:9082" version="2" comment="Internet Explorer 8 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:4421"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:42403" version="1" comment="Mshtml.dll version is less than 8.0.7600.16722" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:12029"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:42393" version="1" comment="Mshtml.dll version is less than 8.0.7600.20861" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:12180"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:20848" version="1" comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:6624"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:114968" version="1" comment="Check if Microsoft Server Bus 1.1 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39035"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:115300" version="1" comment="Check if the version of Microsoft.ServiceBus.dll is less than 2.1.40512.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39286"/>
      <state state_ref="oval:org.mitre.oval:ste:31674"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:114167" version="1" comment="Check if the version of SWORD.DLL is less than 14.0.7123.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39210"/>
      <state state_ref="oval:org.mitre.oval:ste:31098"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113796" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.30" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:30563"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113616" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.8" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:30854"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113462" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.22" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:30534"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:114587" version="1" comment="Check if Microsoft SharePoint Server 2013 Client Components SDK is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:38219"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:114300" version="3" comment="Check if Web Apps Server 2013 SP1 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39205"/>
      <state state_ref="oval:org.mitre.oval:ste:31306"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:114158" version="2" comment="Check if Sharepoint server 2013 SP1 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39142"/>
      <state state_ref="oval:org.mitre.oval:ste:31017"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:114603" version="1" comment="Check if the version of Microsoft.Office.Server.Msg.dll is less than 15.0.4514.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39002"/>
      <state state_ref="oval:org.mitre.oval:ste:24235"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:114600" version="1" comment="Check if the version of wsetupui.dll is less than 15.0.4561.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:39157"/>
      <state state_ref="oval:org.mitre.oval:ste:31289"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:114430" version="1" comment="Check if the version of msoserver.dll is less than 15.0.4615.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:30227"/>
      <state state_ref="oval:org.mitre.oval:ste:31346"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:114066" version="1" comment="Check if the version of Microsoft.sharepoint.client.dll is less than 15.0.4609.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16213"/>
      <state state_ref="oval:org.mitre.oval:ste:31109"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113960" version="1" comment="Check if the version of wsssetup.dll is less than 15.0.4615.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:38235"/>
      <state state_ref="oval:org.mitre.oval:ste:31346"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113418" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:29920"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113364" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:30241"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:100260" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27934"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:100012" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.4" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27995"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:44050" version="1" comment="Check if Sun VirtualBox is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16340"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:41938" version="1" comment="Check if Sun xVM VirtualBox is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15730"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:99972" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:28017"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:99957" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27873"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:99857" version="1" comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27904"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:88842" version="1" comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:24702"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:88836" version="1" comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:24690"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:88607" version="1" comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:24096"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:42006" version="2" comment="Check if Oracle VM VirtualBox is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15297"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:100166" version="1" comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27476"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:100120" version="1" comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27456"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:100117" version="1" comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27928"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:100096" version="1" comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28098"/>
      <state state_ref="oval:org.mitre.oval:ste:27016"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:90023" version="1" comment="Check if Visual Studio Team Foundation Server is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28866"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:89989" version="1" comment="Check if the version of Microsoft.AspNet.SignalR.Core.dll is less than 1.1.21022.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:29074"/>
      <state state_ref="oval:org.mitre.oval:ste:25547"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:99831" version="1" comment="Check if Msoserver.dll is present" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:30360"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:100108" version="1" comment="Check for the existence of SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.WacServer" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:30150"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:90029" version="1" comment="Check if the version of ascalc.dll is less than 14.0.7011.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:28661"/>
      <state state_ref="oval:org.mitre.oval:ste:25427"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:89884" version="1" comment="Check if the version of ascalc.dll is less than 15.0.4545.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:29038"/>
      <state state_ref="oval:org.mitre.oval:ste:25327"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:100103" version="1" comment="Msoserver.Dll is less than 15.0.4551.1007" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:30227"/>
      <state state_ref="oval:org.mitre.oval:ste:27906"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:89964" version="1" comment="Check if Exchange Server 2013 Cumulative Update 3 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:25628"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:89992" version="1" comment="Check if the version of exsetup.exe is less than 15.0.775.41" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:25503"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:89888" version="1" comment="Check if the version of exsetup.exe is less than 15.0.712.31" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:24953"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:89886" version="1" comment="Check if the version of exsetup.exe is less than 8.3.342.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24081"/>
      <state state_ref="oval:org.mitre.oval:ste:25434"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:89845" version="1" comment="Check if the version of exsetup.exe is less than 14.3.174.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:25649"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:89663" version="1" comment="Check if the version of exsetup.exe is less than 14.2.390.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:25043"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:87180" version="1" comment="Check if Microsoft SharePoint Foundation 2013 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26394"/>
      <state state_ref="oval:org.mitre.oval:ste:24179"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:87020" version="1" comment="Check if Microsoft SharePoint Foundation 2010 SP2 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24020"/>
      <state state_ref="oval:org.mitre.oval:ste:24309"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:87199" version="3" comment="Check if the version of onetutil.dll is less than 14.0.7105.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26888"/>
      <state state_ref="oval:org.mitre.oval:ste:23634"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:87074" version="1" comment="Check if the version of microsoft.office.server.native.dll is less than 14.0.7005.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24032"/>
      <state state_ref="oval:org.mitre.oval:ste:24352"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:87023" version="1" comment="Check if the version of Microsoft.office.server.native.dll is less than 15.0.4535.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26607"/>
      <state state_ref="oval:org.mitre.oval:ste:24141"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:86965" version="1" comment="Check if the version of xlsrv.dll is less than 14.0.7104.5000 (sharepoint server)" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26571"/>
      <state state_ref="oval:org.mitre.oval:ste:23691"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:86497" version="2" comment="Check if the version of Onfda.dll is less than 15.0.4535.1000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26407"/>
      <state state_ref="oval:org.mitre.oval:ste:24141"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:86576" version="3" comment="Check if Microsoft Office Web Apps 2010 SP2 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26572"/>
      <state state_ref="oval:org.mitre.oval:ste:23381"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:86608" version="2" comment="Check if Microsoft SharePoint 2010 SP2 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24062"/>
      <state state_ref="oval:org.mitre.oval:ste:23979"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80134" version="1" comment="Check if Microsoft Web Apps is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23425"/>
      <state state_ref="oval:org.mitre.oval:ste:19893"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80139" version="3" comment="Check if Microsoft Office Web Apps SP1 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24131"/>
      <state state_ref="oval:org.mitre.oval:ste:19818"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:87179" version="1" comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23683"/>
      <state state_ref="oval:org.mitre.oval:ste:24088"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:87135" version="1" comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26369"/>
      <state state_ref="oval:org.mitre.oval:ste:24114"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:86178" version="1" comment="Check if Exchange Server 2013 is installed Cumulative Update 1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:23384"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:86283" version="1" comment="Check if Exchange Server 2013 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:23477"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:86716" version="1" comment="Check if Exchange Server 2013 is installed Cumulative Update 2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26779"/>
      <state state_ref="oval:org.mitre.oval:ste:23682"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:85809" version="1" comment="Check if Microsoft Exchange Server 2010 SP3 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23564"/>
      <state state_ref="oval:org.mitre.oval:ste:5469"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:86148" version="1" comment="Check if the version of ExSetup.exe is less than 15.0.620.34" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:23870"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:86102" version="1" comment="Check if the version of ExSetup.exe is less than 15.0.712.28" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:26548"/>
      <state state_ref="oval:org.mitre.oval:ste:23895"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:85977" version="1" comment="Check if the version of ExSetup.exe is less than 14.2.375.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:22603"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:85968" version="1" comment="Check if the version of exsetup.exe is less than 8.3.327.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24081"/>
      <state state_ref="oval:org.mitre.oval:ste:22653"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:85918" version="1" comment="Check if the version of ExSetup.exe is less than 14.3.158.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:23067"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:81231" version="1" comment="Check if version of Oracle GoldenGate Director is 11.1.1.1.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23724"/>
      <state state_ref="oval:org.mitre.oval:ste:20749"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80940" version="1" comment="Check if version for Oracle GoldenGate Veridata is 3.0.0.11.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24195"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:80956" version="2" comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23783"/>
      <state state_ref="oval:org.mitre.oval:ste:19698"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:80229" version="1" comment="Check if Windows Essentials 2012 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23758"/>
      <state state_ref="oval:org.mitre.oval:ste:20712"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80928" version="1" comment="Check if Windows Essentials 2011 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23758"/>
      <state state_ref="oval:org.mitre.oval:ste:20651"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80220" version="1" comment="Check if Windows Essentials is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24148"/>
      <state state_ref="oval:org.mitre.oval:ste:20601"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:81120" version="1" comment="Check if the version of Windowslivewriter.exe is less than 16.4.3508.205" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23851"/>
      <state state_ref="oval:org.mitre.oval:ste:20477"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80872" version="1" comment="Check if the version ExSetup.exe is less than 8.3.298.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24081"/>
      <state state_ref="oval:org.mitre.oval:ste:20432"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80598" version="1" comment="Check if the version ExSetup.exe is less than 14.2.342.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:20072"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80570" version="1" comment="Check if the version of vseshr.dll is less than 8.3.7.207" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24185"/>
      <state state_ref="oval:org.mitre.oval:ste:20405"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80439" version="1" comment="Check if the version ExSetup.exe is less than 14.1.438.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:20061"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80396" version="1" comment="Check if the version ExSetup.exe is less than 14.2.328.10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24092"/>
      <state state_ref="oval:org.mitre.oval:ste:20194"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79624" version="1" comment="Check if the version ExSetup.exe is less than 8.3.297.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24081"/>
      <state state_ref="oval:org.mitre.oval:ste:19800"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:80002" version="1" comment="Check if Microsoft System Center Configuration Manager 2007 R2 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24036"/>
      <state state_ref="oval:org.mitre.oval:ste:19625"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:79954" version="1" comment="Check if Microsoft System Center Configuration Manager 2007 R3 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24054"/>
      <state state_ref="oval:org.mitre.oval:ste:19960"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80024" version="1" comment="Check if Microsoft System Center Configuration Manager 2007 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23424"/>
      <state state_ref="oval:org.mitre.oval:ste:19054"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80097" version="1" comment="Check if Microsoft System Center Configuration Manager 2007 SP2 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23878"/>
      <state state_ref="oval:org.mitre.oval:ste:19796"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80078" version="1" comment="Check if Microsoft Systems Management Server 2003 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23424"/>
      <state state_ref="oval:org.mitre.oval:ste:19789"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:79365" version="1" comment="Check if Microsoft Systems Management Server 2003 SP3 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23937"/>
      <state state_ref="oval:org.mitre.oval:ste:20055"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:80096" version="2" comment="Check if version of ReportingInstall.exe (SCCM 2007) is less than 4.0.6487.2216" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23970"/>
      <state state_ref="oval:org.mitre.oval:ste:19846"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80064" version="1" comment="Check if version of ReportingInstall.exe (SMS 2003) is less than 2.50.4253.3129" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23970"/>
      <state state_ref="oval:org.mitre.oval:ste:19066"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:80166" version="1" comment="Check if Visual Studio Team Foundation Server 2010 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23676"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:79804" version="1" comment="Check if Visual Studio Team Foundation Server 2010 SP1 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23859"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:79715" version="2" comment="Check if the version of Microsoft.TeamFoundation.WebAccess.dll is less than 10.0.40219.417" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23829"/>
      <state state_ref="oval:org.mitre.oval:ste:19971"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:80596" version="1" comment="Check if Microsoft System Center Operations Manager 2007 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24053"/>
      <state state_ref="oval:org.mitre.oval:ste:20030"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80567" version="1" comment="Check if the version of Microsoft System Center Operations Manager 2007 is greater than or equal to 6.0.6278.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23673"/>
      <state state_ref="oval:org.mitre.oval:ste:20330"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80638" version="1" comment="Check if Microsoft System Center Operations Manager 2007 R2 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24053"/>
      <state state_ref="oval:org.mitre.oval:ste:19376"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:80576" version="1" comment="Check if the version of AuditingMessages.dll is less than or equal to 6.0.6278.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24080"/>
      <state state_ref="oval:org.mitre.oval:ste:19787"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80122" version="1" comment="Check if the version of AuditingMessages.dll is less than 6.1.7221.110" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24080"/>
      <state state_ref="oval:org.mitre.oval:ste:20336"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:80504" version="1" comment="Check if SharePoint Server 2013 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23891"/>
      <state state_ref="oval:org.mitre.oval:ste:20292"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:81077" version="1" comment="Check if the version of Microsoft.office.server.dll is less than 15.0.4481.1507" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24129"/>
      <state state_ref="oval:org.mitre.oval:ste:20425"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:79390" version="2" comment="Check if Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24020"/>
      <state state_ref="oval:org.mitre.oval:ste:19815"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80093" version="3" comment="Check if Microsoft SharePoint Server 2010 Service Pack 1 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24062"/>
      <state state_ref="oval:org.mitre.oval:ste:19908"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:79844" version="1" comment="Check if the version of Microsoft.office.server.native.dll is less than 14.0.6108.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24032"/>
      <state state_ref="oval:org.mitre.oval:ste:19858"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79803" version="2" comment="Check if the version of Onfda.dll is less than 14.0.6106.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23783"/>
      <state state_ref="oval:org.mitre.oval:ste:12737"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:79595" version="2" comment="Check if Microsoft Lync 2010 Attendee (user level install) is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23843"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:79186" version="1" comment="Check if Microsoft Lync 2010 Attendant is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23492"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:79499" version="1" comment="Check if Microsoft Lync 2010 Attendee (admin level install) is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23972"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:79642" version="1" comment="Check if Microsoft Lync 2010 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23068"/>
      <state state_ref="oval:org.mitre.oval:ste:19769"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:80016" version="1" comment="Check if version of Attendantconsole.exe is less than 4.0.7577.4098" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24023"/>
      <state state_ref="oval:org.mitre.oval:ste:19700"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79972" version="1" comment="Check if version of Communicator.exe (Lync 2010) is less than 4.0.7577.4098" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23751"/>
      <state state_ref="oval:org.mitre.oval:ste:19700"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79686" version="2" comment="Check if version of ogl.dll (Lync 2010 Attendee for user) is less than 4.0.7577.4098" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24024"/>
      <state state_ref="oval:org.mitre.oval:ste:19700"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79522" version="1" comment="Check if version of ogl.dll (Lync 2010 Attendee for admin) is less than 4.0.7577.4098" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24009"/>
      <state state_ref="oval:org.mitre.oval:ste:19700"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:79536" version="1" comment="Check if FAST Search Server 2010 for SharePoint is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24140"/>
      <state state_ref="oval:org.mitre.oval:ste:19463"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:8521" version="1" comment="Exchange Server 2007 is installed." check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:5992"/>
      <state state_ref="oval:org.mitre.oval:ste:3119"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:80116" version="2" comment="Check if Exchange Server 2007 SP3 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6032"/>
      <state state_ref="oval:org.mitre.oval:ste:5469"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:78247" version="1" comment="Microsoft Exchange Server 2010 SP1 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23564"/>
      <state state_ref="oval:org.mitre.oval:ste:18812"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:78176" version="1" comment="Microsoft Exchange Server 2010 SP2 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23564"/>
      <state state_ref="oval:org.mitre.oval:ste:18859"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:77602" version="1" comment="Microsoft Exchange Server 2010 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23591"/>
      <state state_ref="oval:org.mitre.oval:ste:18889"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:80199" version="2" comment="Check if the version of transcodingservice.exe is less than 14.1.421.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24069"/>
      <state state_ref="oval:org.mitre.oval:ste:19804"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80087" version="2" comment="Check if the version of transcodingservice.exe is less than 8.3.279.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23395"/>
      <state state_ref="oval:org.mitre.oval:ste:19614"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:80085" version="1" comment="Check if the version of Microsoft.sharepoint.search.extended.administration.dll is less than 14.0.334.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:23754"/>
      <state state_ref="oval:org.mitre.oval:ste:19994"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79908" version="2" comment="Check if the version of transcodingservice.exe is less than 14.2.318.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:24069"/>
      <state state_ref="oval:org.mitre.oval:ste:19493"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:78074" version="1" comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6113.5000" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15529"/>
      <state state_ref="oval:org.mitre.oval:ste:18595"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:77961" version="1" comment="OWSSVR.DLL version is less than 14.0.6114.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16246"/>
      <state state_ref="oval:org.mitre.oval:ste:18732"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:77867" version="2" comment="Anti-Cross Site Scripting Library 3.x or 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1436"/>
      <state state_ref="oval:org.mitre.oval:ste:18471"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:42957" version="1" comment="the version of Onetutil.dll is less than 12.0.6565.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:12206"/>
      <state state_ref="oval:org.mitre.oval:ste:13076"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:27622" version="2" comment="Microsoft Windows SharePoint Services 3.0 are installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:12311"/>
      <state state_ref="oval:org.mitre.oval:ste:7274"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:43555" version="2" comment="SharePoint Server 2010 is installed." check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16204"/>
      <state state_ref="oval:org.mitre.oval:ste:12994"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:43939" version="1" comment="SharePoint Foundation 2010 is installed." check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16233"/>
      <state state_ref="oval:org.mitre.oval:ste:12950"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:43900" version="1" comment="Eawfap.dll version is less than 14.0.6106.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16268"/>
      <state state_ref="oval:org.mitre.oval:ste:13043"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:43892" version="1" comment="Microsoft.office.policy.dll version is less than 14.0.6106.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15985"/>
      <state state_ref="oval:org.mitre.oval:ste:12754"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:43889" version="1" comment="OWSSVR.DLL version is less than 14.0.6106.5008" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16246"/>
      <state state_ref="oval:org.mitre.oval:ste:13090"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:43686" version="1" comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6106.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15529"/>
      <state state_ref="oval:org.mitre.oval:ste:13021"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:43419" version="1" comment="Microsoft.SharePoint.Client.dll version is less than 14.0.6106.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:16213"/>
      <state state_ref="oval:org.mitre.oval:ste:12982"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:43358" version="1" comment="Microsoft.office.server.dll version is less than 14.0.6106.5001" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15305"/>
      <state state_ref="oval:org.mitre.oval:ste:12699"/>
    </file_test>
  </tests>
  <objects>
    <registry_object id="oval:org.mitre.oval:obj:2686" version="3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Office\\12\.0\\Registration\\\{90120000-110D-0000-[01]000-0000000FF1CE\}$</key>
      <name>ProductName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:43939" version="1" comment="Object holds the details of Microsoft.SharePoint.Portal.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:834" var_check="at least one"/>
      <filename>Microsoft.SharePoint.Portal.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:43159" version="1" comment="Object holds the information of Microsoft.Office.Server.Search.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1086" var_check="at least one"/>
      <filename>Microsoft.Office.Server.Search.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:43915" version="1" comment="Object holds the details of msoserverintl.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1431" var_check="at least one"/>
      <filename>msoserverintl.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:43884" version="1" comment="Object holds the details of wwintl.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1672" var_check="at least one"/>
      <filename>wwintl.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:44052" version="1" comment="Object holds the details of vutils.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1902" var_check="at least one"/>
      <filename>vutils.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:24128" version="1" comment="Object holds the details of Msoserver.Dll(Sharepoint Server)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1921"/>
      <filename>Msoserver.Dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:43614" version="1" comment="Object holds the path to microsoft.office.infopath.server.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1870" var_check="at least one"/>
      <filename>microsoft.office.infopath.server.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:44137" version="1" comment="Object holds the path to Office Server 15 bin directory" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Office Server\15.0</key>
      <name>BinPath</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:26773" version="1" comment="Object holds the details of xlsrv.dll in Microsoft Office 2013 Excel Services" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1658" var_check="at least one"/>
      <filename>xlsrv.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:44015" version="2" comment="Object holds the details of stswel.dll (Foundation 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1569" var_check="at least one"/>
      <filename>stswel.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:41939" version="1" comment="Object holds the path to Deploy.resources.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1930" var_check="at least one"/>
      <filename>Deploy.resources.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:42109" version="1" comment="Object holds the path to Microsoft.Rtc.Acd.Workflow.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1370" var_check="at least one"/>
      <filename>Microsoft.Rtc.Acd.Workflow.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:24372" version="1" comment="The registry holds if Microsoft Lync Server 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{.*\}$</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:42312" version="1" comment="Object holds the path to wrtces.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1410" var_check="at least one"/>
      <filename>wrtces.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:42322" version="1" comment="Object holds the path to SIPStack.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1410" var_check="at least one"/>
      <filename>SIPStack.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:42038" version="1" comment="Object holds the path to Microsoft Lync Server" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Real-Time Communications\{A593FD00-64F1-4288-A6F4-E699ED9DCA35}</key>
      <name>InstallDir</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:247" version="2" comment="This registry key identifies the version of internet Explorer" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Internet Explorer</key>
      <name>Version</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:222" version="1" comment="The path to the mshtml.dll file in the system root" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200" var_check="all"/>
      <filename>mshtml.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:39286" version="1" comment="Object holds the path to Microsoft.ServiceBus.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:953" var_check="at least one"/>
      <filename>Microsoft.ServiceBus.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:39035" version="1" comment="Object holds if Microsoft Service Bus 1.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Service Bus\1.1</key>
      <name>INSTALLDIR</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:39210" version="1" comment="Object holds the path to SWORD.DLL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1938" var_check="at least one"/>
      <filename>SWORD.DLL</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:39236" version="1" comment="The registry holds the install location of sharepoint server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.WCSERVER</key>
      <name>InstallLocation</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:38219" version="1" comment="Registry holds if Microsoft SharePoint Server 2013 Client Components SDK is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\SharePoint Client Components\15.0</key>
      <name>Location</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:39205" version="3" comment="Registry holds if Web Apps Server 2013 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{90150000-101F-0401-1000-0000000FF1CE\}_Office15\.WacServer\-\{[\w\-]+\}$</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:39142" version="2" comment="Registry holds if sharepoint server 2013 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{90150000-1014-0000-1000-0000000FF1CE}_Office15\.OSERVER\{[\w\-]+\}$</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:39002" version="1" comment="Object holds the path to Microsoft.Office.Server.Msg.dll (sharepoint 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1682" var_check="at least one"/>
      <filename>Microsoft.Office.Server.Msg.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:39157" version="1" comment="Object holds the path to wsetupui.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1227" var_check="at least one"/>
      <filename>wsetupui.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:38235" version="1" comment="Object holds the path to Wsssetup.dll (foundation 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1886" var_check="at least one"/>
      <filename>Wsssetup.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:16340" version="1" comment="Object holds if Sun VirtualBox is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Sun\VirtualBox</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:15730" version="1" comment="Object holds if Sun xVM VirtualBox is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Sun\xVM VirtualBox</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:15297" version="2" comment="Object holds if Oracle VM VirtualBox is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Oracle\VirtualBox</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:28098" version="1" comment="The directory of VirtualBox.exe in VirtualBox of versions 3.2.0 and greater" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1088" var_check="all"/>
      <filename>VirtualBox.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:28316" version="1" comment="Object holds the Oracle VM VirtualBox directory of versions 3.2.0 and greater" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Oracle\VirtualBox</key>
      <name>InstallDir</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:29074" version="1" comment="Object holds the file Microsoft.AspNet.SignalR.Core.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1526" var_check="at least one"/>
      <filename>Microsoft.AspNet.SignalR.Core.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:28866" version="1" comment="Object holds if Visual Studio TFS is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\TeamFoundationServer\12.0</key>
      <name>InstallPath</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:30360" version="1" comment="Object holds the details of Msoserver.Dll (Office Web Apps 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1064" var_check="at least one"/>
      <filename>Msoserver.Dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:30150" version="1" comment="Object holds the Path to install location of Microsoft Office Web Apps Server 2013" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.WacServer</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:28661" version="1" comment="Object holds the file ascalc.dll in SharePoint Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1138" var_check="at least one"/>
      <filename>ascalc.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:29038" version="1" comment="Object holds the details of ascalc.dll in Microsoft Office 2013" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1658" var_check="at least one"/>
      <filename>ascalc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:26037" version="1" comment="Object that holds the install location of SharePoint Server 2013" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.OSERVER</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:30227" version="1" comment="Object holds the path to Msoserver.Dll (web apps 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1402" var_check="at least one"/>
      <filename>Msoserver.Dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23503" version="1" comment="Object holds Web apps 2010 InstallLocation" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.WCSERVER</key>
      <name>InstallLocation</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:26394" version="1" comment="The registry holds if SharePoint Foundation 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90150000-1014-0000-1000-0000000FF1CE}</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:26888" version="2" comment="Object holds the file info of Onetutil.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1390" var_check="at least one"/>
      <filename>Onetutil.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:26607" version="1" comment="Object holds the path to Microsoft.office.server.native.dll (sharepoint 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1682" var_check="at least one"/>
      <filename>Microsoft.office.server.native.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:26495" version="1" comment="The registry holds the install location of sharepoint server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.OSERVER</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:26571" version="1" comment="Object holds the file xlsrv.dll in SharePoint Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1138" var_check="at least one"/>
      <filename>xlsrv.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:26407" version="2" comment="Object holds the path to Onfda.dll (SharePoint Server 2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1569" var_check="at least one"/>
      <filename>Onfda.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:26572" version="3" comment="Object that holds the Microsoft Web Apps 2010 SP 2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{90140000\-1141\-0407\-1000\-0000000FF1CE\}_Office14\.WCSERVER_\{[\w\-]+\}$</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23425" version="1" comment="The registry holds if Microsoft Web Apps is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.WCSERVER</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24131" version="3" comment="Object holds the string Microsoft Office Web Apps Service Pack 1 (SP1)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{90140000\-112D\-0000\-1000\-0000000FF1CE\}_Office14\.WCSERVER_\{[\w\-]+\}$</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23683" version="1" comment="Object holds the details of Msoserver.Dll(Web Apps)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1263"/>
      <filename>Msoserver.Dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23950" version="1" comment="Object holds the installation path for web apps 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.WCSERVER</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:26369" version="1" comment="Object holds the path to WdsrvWorker.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1614" var_check="at least one"/>
      <filename>WdsrvWorker.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:26779" version="1" comment="Object holds if Exchange Server 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Exchange v15</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:26548" version="1" comment="Object holds the details of ExSetup.exe (2013)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1738"/>
      <filename>ExSetup.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:26763" version="1" comment="Object holds the install path for Microsoft Exchange Server 2013" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\ExchangeServer\v15\Setup</key>
      <name>MsiInstallPath</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23724" version="1" comment="Version of Oracle GoldenGate Director is 11.1.1.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\[\d]*-[\d]*-[\d]*-[\d]*$</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24195" version="1" comment="Version of Oracle GoldenGate Veridata is 3.0.0.11.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Oracle GoldenGate Veridata 3.0.0.11.0</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23758" version="1" comment="The registry holds the display version of Windows Essentials" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24148" version="1" comment="The registry holds if Windows Essentials is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23851" version="1" comment="Object holds the path to Windowslivewriter.exe" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1592"/>
      <filename>WindowsLiveWriter.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:24228" version="1" comment="The registry holds the install location of Windows Essentials" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24185" version="1" comment="Object holds the file vseshr.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1381"/>
      <filename>vseshr.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:24092" version="1" comment="Object holds the details of ExSetup.exe (2010)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1376"/>
      <filename>ExSetup.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:24068" version="1" comment="Object holds the install path for Microsoft Exchange Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\ExchangeServer\v14\Setup</key>
      <name>MsiInstallPath</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24081" version="1" comment="Object holds the details of ExSetup.exe (2007)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1555"/>
      <filename>ExSetup.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23474" version="1" comment="Object holds the install path for Microsoft Exchange Server 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Exchange\Setup</key>
      <name>MsiInstallPath</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24036" version="1" comment="Object holds DisplayName of System Center Configuration Manager 2007 R2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{006CCC4E-4FEB-4ED1-8587-037656905DC8}</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24054" version="1" comment="Object holds DisplayName of System Center Configuration Manager 2007 R3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5CF55004-EEC4-406F-AF05-2291F1395388}</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23878" version="1" comment="Object holds UI Version of System Center Configuration Manager 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\ConfigMgr\Setup</key>
      <name>Full UI Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23424" version="1" comment="Object holds DisplayName of Systems Management Servers" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SMS .*$</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23937" version="1" comment="Object holds version of Systems Management Server 2003" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\SMS\Setup</key>
      <name>Full Version</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23970" version="1" comment="Object holds file path for Reportinginstall.exe" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1340" var_check="all"/>
      <filename>reportinginstall.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23949" version="1" comment="Object holds Install Directory path for SMS/SCCM" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\SMS\Setup</key>
      <name>Installation Directory</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23676" version="1" comment="Object holds the install location of Visual Studio Team Foundation Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\TeamFoundationServer\10.0</key>
      <name>InstallPath</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23859" version="1" comment="Object holds if Visual Studio Team Foundation Server 2010 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Updates\Microsoft Team Foundation Server 2010 - ENU\SP1\KB2182621</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23829" version="2" comment="Object holds the details of Microsoft.TeamFoundation.WebAccess.dl" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1065" operation="pattern match"/>
      <filename>Microsoft.TeamFoundation.WebAccess.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:219" version="1" comment="This registry key identifies the system root." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>SystemRoot</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23673" version="1" comment="Object holds the version of System Center Operations Manager 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Microsoft Operations Manager\3.0\Setup</key>
      <name>ServerVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24053" version="1" comment="Object holds if System Center Operations Manager 2007 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Microsoft Operations Manager\3.0\Setup</key>
      <name>Product</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24080" version="1" comment="Object holds the version of AuditingMessages.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1687"/>
      <filename>AuditingMessages.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23919" version="1" comment="Object holds the installation path of System Operation Center Manager" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Microsoft Operations Manager\3.0\Setup</key>
      <name>InstallDirectory</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23891" version="1" comment="The registry holds if SharePoint Server 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.OSERVER</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24129" version="1" comment="Object holds the path to Microsoft.office.server.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1086" var_check="all"/>
      <filename>Microsoft.office.server.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:24020" version="2" comment="Object holds if Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{90140000-1014-0000-1000-0000000FF1CE}_Office14\.WSS_\{[\w\-]+}$</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24062" version="3" comment="Object holds if Microsoft SharePoint Server 2010 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.OSERVER</key>
      <name>DisplayVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24032" version="1" comment="Object holds the path to Microsoft.office.server.native.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1138" var_check="all"/>
      <filename>Microsoft.office.server.native.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23943" version="1" comment="The registry holds the install location of sharepoint server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.OSERVER</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23783" version="2" comment="Object holds the path to Onfda.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1390" var_check="all"/>
      <filename>Onfda.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23068" version="1" comment="Object holds Microsoft Communicator 2007 R2/Microsoft Lync 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Communicator</key>
      <name/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24023" version="1" comment="Object holds path for Attendantconsole.exe" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1095"/>
      <filename>Attendantconsole.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23492" version="1" comment="Object holds Microsoft Lync 2010 Attendant" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AttendantConsole.exe</key>
      <name>path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23751" version="1" comment="Object holds path for Communicator.exe" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1463"/>
      <filename>Communicator.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23858" version="1" comment="Object holds filelocation for Commmunicator.exe" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Communicator</key>
      <name>InstallationDirectory</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24024" version="2" comment="Object holds path for Ogl.dll (Lync 2010 Attendee for user)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1779" var_check="all"/>
      <filename>ogl.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23843" version="2" comment="Object holds Microsoft Lync 2010 Attendee (user level install)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_USERS</hive>
      <key operation="pattern match">^S-.*\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\AttendeeCommunicator\.exe$</key>
      <name>path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24009" version="1" comment="Object holds path for Ogl.dll (Lync 2010 attendee for admin)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1822" var_check="all"/>
      <filename>ogl.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23972" version="1" comment="Object holds Microsoft Lync 2010 Attendee (admin level install)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AttendeeCommunicator.exe</key>
      <name>path</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:24140" version="1" comment="Object holds if FAST Search Server 2010 for SharePoint is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\FAST Search Server\Setup</key>
      <name>Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:5992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Exchange\Setup</key>
      <name>MsiProductMajor</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:6032" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Exchange\Setup</key>
      <name>MsiProductMinor</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23564" version="1" comment="The registry key that holds the MsiProductMinor" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\ExchangeServer\v14\Setup</key>
      <name>MsiProductMinor</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:23591" version="1" comment="The registry key that holds the MsiProductMajor" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\ExchangeServer\v14\Setup</key>
      <name>MsiProductMajor</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23395" version="1" comment="Object holds the details of transcodingservice.exe (2007)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1320"/>
      <filename>transcodingservice.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23606" version="1" comment="Object holds the install path for Microsoft Exchange Server 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Exchange\Setup</key>
      <name>MsiInstallPath</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:23754" version="1" comment="Object holds the details of Microsoft.sharepoint.search.extended.administration.dll" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1381"/>
      <filename>Microsoft.sharepoint.search.extended.administration.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:24125" version="1" comment="Object holds the path for FAST Search Server 2010 for SharePoint" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\FAST Search Server\Setup</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:24069" version="1" comment="Object holds the details of transcodingservice.exe (2010)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1542"/>
      <filename>transcodingservice.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:23243" version="1" comment="Object holds the install path for Microsoft Exchange Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\ExchangeServer\v14\Setup</key>
      <name>MsiInstallPath</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1436" version="3" comment="Registry key for HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\.*!DisplayName" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*$</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:12206" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:834" var_check="all"/>
      <filename>Onetutil.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:12311" version="2" comment="Registry that holds the DisplayName of the SharePoint Services 3.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{90120000-1014-0000-[01]000-0000000FF1CE\}$</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:16204" version="2" comment="Object holds DisplayName of SharePoint Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office14.OSERVER</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:16233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-1110-0000-1000-0000000FF1CE}</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:16268" version="1" comment="Eawfap.dll file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1050" var_check="all"/>
      <filename>Eawfap.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:15985" version="1" comment="SharePoint Server 2010 - Microsoft.office.policy.dll file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1050" var_check="all"/>
      <filename>Microsoft.office.policy.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:16246" version="1" comment="OWSSVR.DLL file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1050" var_check="all"/>
      <filename>OWSSVR.DLL</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:15529" version="1" comment="Microsoft.SharePoint.Taxonomy.dll file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1050" var_check="all"/>
      <filename>Microsoft.SharePoint.Taxonomy.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:16213" version="1" comment="SharePoint Server 2010 - Microsoft.SharePoint.Client.dll file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1050" var_check="all"/>
      <filename>Microsoft.SharePoint.Client.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:15305" version="1" comment="Microsoft.office.server.dll file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1050" var_check="all"/>
      <filename>Microsoft.office.server.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:281" version="1" comment="The registry key that identifies the location of the common files directory." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
      <name>CommonFilesDir</name>
    </registry_object>
  </objects>
  <states>
    <registry_state id="oval:org.mitre.oval:ste:3235" version="2" comment="The registry key has a value of Microsoft Office SharePoint Server 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Office SharePoint Server 2007</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:38672" version="1" comment="State holds if the version is less than 15.0.4719.1002" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4719.1002</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38541" version="1" comment="State holds if the version is less than 14.0.7149.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7149.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38210" version="1" comment="State holds if the version is less than 12.0.6721.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">12.0.6721.5000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:38813" version="1" comment="State holds the value Microsoft Exchange Server 2013 Cumulative Update 8" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange Server 2013 Cumulative Update 8</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:39001" version="1" comment="State holds if the version is less than 15.0.847.41" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.847.41</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38872" version="1" comment="State holds if the version is less than 15.0.1076.011" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.1076.011</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38396" version="1" comment="State holds if the version is less than 15.0.4711.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4711.1000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3489" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:37587" version="1" comment="State holds if the version is less than 14.03.0224.001" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.03.0224.001</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:37084" version="1" comment="State holds if the version is less than 8.03.0389.002" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.03.0389.002</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:37662" version="1" comment="State holds the value Microsoft Exchange Server 2013 Cumulative Update 6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange Server 2013 Cumulative Update 6</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:37067" version="1" comment="State holds if the version is less than 15.00.0847.035" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.00.0847.035</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:36871" version="1" comment="State holds if the version is less than 15.00.0995.034" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.00.0995.034</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:38334" version="1" comment="State holds the value Microsoft Exchange Server 2013 Cumulative Update 7" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange Server 2013 Cumulative Update 7</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:38372" version="1" comment="State holds if the version is less than 15.0.847.38" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.847.38</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38464" version="1" comment="State holds if the version is less than 15.0.1044.29" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.1044.29</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:37582" version="1" comment="State holds if the version is less than 15.0.4697.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4697.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38477" version="1" comment="State holds if the version is less than 15.0.4631.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4631.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38439" version="1" comment="State holds if the version is less than 14.0.7145.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7145.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38421" version="1" comment="State holds if the version is less than 15.0.4699.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4699.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38093" version="1" comment="State holds if the version is less than 15.0.4701.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4701.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:37438" version="1" comment="State holds if the version is less than 14.0.7137.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7137.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31615" version="1" comment="State holds if the version is less than 5.0.8308.420" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.8308.420</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:33946" version="1" comment="State matches if the version is less than 4.0.7577.276" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.7577.276</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:34174" version="1" comment="State matches if Lync Server 2010 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft Lync Server 2010.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:20728" version="1" comment="State matches if Lync Server 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft Lync Server 2013.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:33474" version="1" comment="State matches if the version is less than 4.0.7577.230" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.7577.230</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:33391" version="1" comment="State matches if the version is less than 5.0.8308.803" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.8308.803</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:12091" version="2" comment="The registry key has a value that matches 9.*" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^9\.0\..*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:33464" version="1" comment="State holds if the version is less than 15.0.4641.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4641.1000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:4421" version="1" comment="The registry key has a value that matches 8.*" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^8\..*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:12029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.7600.16722</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:12180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.7600.20861</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:6624" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">8.0.7600.20000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31674" version="1" comment="State holds if the version is less than 2.1.40512.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.1.40512.2</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31098" version="1" comment="State matches if the version is less than 14.0.7123.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7123.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:30563" version="1" comment="State matches if Sun VM VirtualBox version is less than or equals to 4.1.30" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.1.30</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:30854" version="1" comment="State matches if Oracle VM VirtualBox version is less than  or equal 4.3.8" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.3.8</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:30534" version="1" comment="State matches if Sun VM VirtualBox version is less than or equals to 4.2.22" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.2.22</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:31306" version="1" comment="State matches if Web Apps Server 2013 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack 1 for Microsoft Office Web Apps Server .*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:31017" version="1" comment="State matches if sharepoint server 2013 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack 1 for Microsoft SharePoint Server 2013 .*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:24235" version="1" comment="State matches if the version is less than 15.0.4514.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4514.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31289" version="1" comment="State holds if the version is less than 15.0.4561.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4561.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31109" version="1" comment="State matches if the version is less than 15.0.4609.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4609.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31346" version="1" comment="State holds if the version is less than 15.0.4615.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4615.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:29920" version="1" comment="State matches if Sun VM VirtualBox version is less than or equals to 4.2.20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.2.20</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:30241" version="1" comment="State matches if Oracle VM VirtualBox version is less than  or equal 4.3.6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.3.6</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27934" version="1" comment="State matches if Sun VM VirtualBox version is less than or equals to 4.2.20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.2.20</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27995" version="1" comment="State matches if Oracle VM VirtualBox version is less than  or equal 4.3.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.3.4</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:28017" version="1" comment="State matches if Sun VM VirtualBox version is less than or equals to 4.2.18" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.2.18</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27873" version="1" comment="State matches if Sun VM VirtualBox version is less than or equals to 4.1.28" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.1.28</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27904" version="1" comment="State matches if Sun VM VirtualBox version is greater than or equals to 4.2.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">4.2.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24702" version="1" comment="State matches if Oracle VM VirtualBox version is greater than or equals to 3.2.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">3.2.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24690" version="1" comment="State matches if Sun VM VirtualBox version is greater than or equals to 4.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">4.1.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24096" version="1" comment="State matches if Oracle VM VirtualBox version is greater than or equals to 4.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">4.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27476" version="1" comment="State matches if Oracle VM VirtualBox version is less than  or equal 4.3.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.3.2</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27456" version="1" comment="State matches if Oracle VM VirtualBox version is greater than or equals 4.3.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">4.3.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27928" version="1" comment="State matches if Oracle VM VirtualBox version is less than or equals to 3.2.18" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">3.2.18</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27016" version="1" comment="State matches if Oracle VM VirtualBox version is less than or equals to 4.0.20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">4.0.20</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25547" version="1" comment="State holds if the version is less than 1.1.21022.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.1.21022.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25427" version="1" comment="State matches if the version is less than 14.0.7011.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7011.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25327" version="1" comment="State matches if the version is less than 15.0.4545.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4545.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27906" version="1" comment="State matches if the version is less than 15.0.4551.1007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4551.1007</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:25628" version="1" comment="State holds the value Microsoft Exchange Server 2013 Cumulative Update 3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange Server 2013 Cumulative Update 3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:25503" version="1" comment="State holds if the version is less than 15.0.775.41" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.775.41</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24953" version="1" comment="State holds if the version is less than 15.0.712.31" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.712.31</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25434" version="1" comment="State holds if the version is less than 8.3.342.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.3.342.4</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25649" version="1" comment="State holds if the version is less than 14.3.174.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.3.174.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25043" version="1" comment="State holds if the version is less than 14.2.390.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.2.390.3</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:24179" version="1" comment="State matches if SharePoint Foundation 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft SharePoint Foundation 2013 .*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:24309" version="1" comment="State matches if Microsoft SharePoint Foundation 2010 SP2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack 2 for Microsoft SharePoint Foundation 2010 .*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:23634" version="1" comment="State holds if the version is less than 14.0.7105.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7105.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24352" version="1" comment="State matches if the version is less than 14.0.7005.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7005.1000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:23691" version="1" comment="State matches if the version is less than 14.0.7104.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7104.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24141" version="1" comment="State matches if the version is less than 15.0.4535.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4535.1000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:23381" version="1" comment="State holds the string Microsoft Office Web Apps Service Pack 2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack 2 for Microsoft Office Web Apps.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:23979" version="2" comment="State matches if the version is equal to 14.0.7015.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="version">14.0.7015.1000</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19893" version="1" comment="State matches if Microsoft Web Apps is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft.* Office Web Apps$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19818" version="1" comment="State holds the string Microsoft Office Web Apps Service Pack1 (SP1)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Office Web Apps Service Pack 1 (SP1)</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:24088" version="1" comment="State matches if the version is less than 14.0.7106.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.7106.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24114" version="1" comment="State matches if the version is less than 14.0.6112.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6112.5000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:23384" version="1" comment="State holds the value Microsoft Exchange Server 2013 Cumulative Update 1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange Server 2013 Cumulative Update 1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:23477" version="1" comment="State holds the value Microsoft Exchange Server 2013" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft Exchange Server 2013.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:23682" version="1" comment="State holds the value Microsoft Exchange Server 2013 Cumulative Update 2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange Server 2013 Cumulative Update 2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:23870" version="1" comment="State holds if the version is less than 15.0.620.34" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.620.34</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:23895" version="1" comment="State holds if the version is less than 15.0.712.28" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.712.28</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:22603" version="1" comment="State holds if the version is less than 14.2.375.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.2.375.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:22653" version="1" comment="State holds if the version is less than 8.3.327.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.3.327.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:23067" version="1" comment="State holds if the version is less than 14.3.158.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.3.158.1</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:20749" version="1" comment="Version of Oracle GoldenGate Director Server is 11.1.1.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Oracle GoldenGate Director Server 11.1.1.1.0[_\d]*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:19698" version="1" comment="State matches if the version is less than 14.0.6134.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6134.5000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:20712" version="1" comment="State matches if Windows Essentials 2012 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^16\..*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:20651" version="1" comment="State matches if Windows Essentials 2011 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^15\..*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:20601" version="1" comment="State matches if Windows Essentials is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Windows Live Essentials</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:20477" version="1" comment="16.4.3508.205" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">16.4.3508.205</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20432" version="1" comment="State matches if the version is less than 8.3.298.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.3.298.3</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20072" version="1" comment="State matches if the version is less than 14.2.342.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.2.342.2</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20405" version="1" comment="State holds if the version is less than 8.3.7.207" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.3.7.207</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20061" version="1" comment="State matches if version is less than 14.1.438.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.1.438.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20194" version="1" comment="State matches if version is less than 14.2.328.10" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.2.328.10</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:19800" version="1" comment="State matches if version is less than 8.3.297.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.3.297.2</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:19625" version="1" comment="State matches the string System Center Configuration Manager 2007 R2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft System Center Configuration Manager 2007 R2</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19960" version="1" comment="tate matches the string System Center Configuration Manager 2007 R3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft System Center Configuration Manager 2007 R3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19054" version="1" comment="State matches the string System Center Configuration Manager 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft System Center Configuration Manager 2007.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19796" version="1" comment="State matches if version is greater than or equal to 4.00.6487.2000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="version" operation="greater than or equal">4.00.6487.2000</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19789" version="1" comment="State matches the string Systems Management Server 2003" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^.*Microsoft Systems Management Server 2003.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:20055" version="1" comment="State matches if version is greater than or equal to 2.50.4253.3000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="greater than or equal" datatype="version">2.50.4253.3000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:19846" version="2" comment="State matches if version is less than 4.0.6487.2216" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.6487.2216</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:19066" version="1" comment="State matches if version is less than 2.50.4253.3129" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows"/>
    <file_state id="oval:org.mitre.oval:ste:19971" version="1" comment="State holds if the version is less than 10.0.40219.417" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.40219.417</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:20030" version="1" comment="State holds the string System Center Operations Manager 2007" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>System Center Operations Manager 2007</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:20330" version="1" comment="State holds if the value is greater than or equal to 6.0.6278.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="greater than or equal" datatype="version">6.0.6278.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19376" version="1" comment="State holds the string System Center Operations Manager 2007 R2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>System Center Operations Manager 2007 R2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:19787" version="1" comment="State holds if the version is less than or equal to 6.0.6278.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">6.0.6278.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20336" version="1" comment="State holds if the version is less than 6.1.7221.110" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.7221.110</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:20292" version="1" comment="State matches if Microsoft SharePoint Server 2013 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft SharePoint Server 2013</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:20425" version="1" comment="State matches if the version is less than 15.0.4481.1507" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">15.0.4481.1507</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:19815" version="1" comment="State holds if Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft SharePoint Foundation 2010 Service Pack 1 (SP1)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:19908" version="2" comment="State matches if the version is equal to 14.0.6029.1000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="version">14.0.6029.1000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:19858" version="1" comment="State matches if the version is less than 14.0.6108.5000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6108.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:12737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:19769" version="1" comment="State holds the string Microsoft Lync 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Lync 2010</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:19700" version="1" comment="State macthes if version is less than 4.0.7577.4098" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.7577.4098</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:19463" version="1" comment="State holds the value 14.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="version">14.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:3119" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">8</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:5469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:18812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:18859" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">2</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:18889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">14</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:19804" version="2" comment="State holds if the version is less than 14.1.421.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.1.421.2</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:19614" version="2" comment="State holds if the version is less than 8.3.279.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.3.279.4</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:19994" version="1" comment="State holds if the version is less than 14.0.334.11" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.334.11</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:19493" version="2" comment="State holds if the version is less than 14.2.318.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.2.318.4</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:18595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6113.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:18732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6114.5001</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:18471" version="1" comment="The registry key value matches with Microsoft AntiXSS v3.x or 4.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft AntiXSS v(3\.\d|4\.0).*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:13076" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">12.0.6565.5001</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:7274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Microsoft Windows SharePoint Services 3\.0.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:12994" version="1" comment="The registry key has a value of Microsoft SharePoint Server 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft SharePoint Server 2010</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:12950" version="1" comment="The registry key has a value of Microsoft SharePoint Foundation 2010" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft SharePoint Foundation 2010</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:13043" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5001</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:12754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5001</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:13090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5008</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:13021" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5001</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:12982" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5001</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:12699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">14.0.6106.5001</version>
    </file_state>
  </states>
  <variables>
    <local_variable id="oval:org.mitre.oval:var:1431" version="1" comment="Variable holds the path to ConversionServer (Sharepoint 2013)" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:26495" item_field="value"/>
        <literal_component>\15.0\WebServices\ConversionServices\1033</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1672" version="1" comment="Full path to WordServer\Core" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:26495" item_field="value"/>
        <literal_component>\15.0\WebServices\ConversionServices</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1902" version="1" comment="Variable holds the path to VisioGraphicsServer\bin" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:26037" item_field="value"/>
        <literal_component>\15.0\WebServices\Shared\VisioGraphicsServer\Bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1921" version="1" comment="Variable holds the path to Word Server folder of Microsoft Sharepoint Server 2010" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23943" item_field="value"/>
        <literal_component>\14.0\WebServices\WordServer\Core</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1870" version="1" comment="Variable holds the path to BIN folder(Sharepoint 2013)" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:44137" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1930" version="1" comment="Full path to Microsoft Lync Server's Deployment folder" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:42038" item_field="value"/>
        <literal_component>\Deployment\de-DE</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1370" version="1" comment="Full path to Microsoft Lync Server's Response Group folder" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:42038" item_field="value"/>
        <literal_component>\Application Host\Applications\Response Group</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1410" version="1" comment="Full path to Microsoft Lync Server's Core folder" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:42038" item_field="value"/>
        <literal_component>\Server\Core</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:200" version="1" comment="Windows System32 directory" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\System32</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:953" version="1" comment="Variable holds the install path of Microsoft Service Bus 1.1" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:39035" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1938" version="1" comment="Full path to WordServer\Core" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:39236" item_field="value"/>
        <literal_component>\14.0\WebServices\ConversionService\Bin\Converter</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1227" version="1" comment="Full path to foundation 2013 Server Setup Controller WSS.en-us folder" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:281" item_field="value"/>
        <literal_component>\Microsoft Shared\SERVER15\Server Setup Controller\WSS.en-us</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1886" version="1" comment="Full path to foundation 2013 Server Setup Controller folder" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:281" item_field="value"/>
        <literal_component>\Microsoft Shared\SERVER15\Server Setup Controller</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1088" version="1" comment="The VirtualBox directory of versions 3.2.0 and greater" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:28316"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1526" version="1" comment="Variable holds the path to TFS Bin Directory (2013)" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:28866" item_field="value"/>
        <literal_component>Application Tier\Web Services\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1064" version="1" comment="Variable holds the path to Msoserver.Dll" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:30150" item_field="value"/>
        <literal_component>\PPTConversionService\bin\Converter</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1658" version="1" comment="Variable holds the bin directory of Excel Services in SharePoint Server 2013" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:26037" item_field="value"/>
        <literal_component>\15.0\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1402" version="1" comment="Path to Converter Directory in Web Apps 2013" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23503" item_field="value"/>
        <literal_component>\15.0\WebServices\ConversionService\Bin\Converter</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1682" version="1" comment="sharepoint server 2013" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:26495" item_field="value"/>
        <literal_component>\15.0\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1569" version="2" comment="Default comment, please change" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:281" item_field="value"/>
        <literal_component>\Microsoft Shared\web server extensions\15\BIN</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1263" version="1" comment="Variable holds the path to Converter Directory in Web Apps 2010" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23950" item_field="value"/>
        <literal_component>\14.0\WebServices\ConversionService\Bin\Converter</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1614" version="1" comment="Full path to WordServer\Core" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23943" item_field="value"/>
        <literal_component>\14.0\WebServices\WordServer\Core</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1738" version="1" comment="Var holds the path to Exchange Server\V15\Bin directory" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:26763" item_field="value"/>
        <literal_component>\Bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1592" version="1" comment="Full path to Windowslivewriter.exe" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:24228" item_field="value"/>
        <literal_component>Writer</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1376" version="1" comment="Var holds the path to Exchange Server\V14\Bin directory" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:24068" item_field="value"/>
        <literal_component>\Bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1555" version="1" comment="Var holds the path to Exchange Server\Bin directory" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23474" item_field="value"/>
        <literal_component>\Bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1340" version="1" comment="Var holds path for SMS/SCCM bin directory" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23949" item_field="value"/>
        <literal_component>\bin\i386</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1065" version="2" comment="Variable holds the path to Visual Studio Team Foundation Server 2010" datatype="string">
      <concat>
        <literal_component>^</literal_component>
        <escape_regex>
          <object_component object_ref="oval:org.mitre.oval:obj:219" item_field="value"/>
        </escape_regex>
        <literal_component>\\assembly\\GAC_MSIL\\Microsoft\.TeamFoundation\.WebAccess\\10\.0\.0\.0__\w+$</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1687" version="1" comment="Variable holds the path to SOCM Installation directory" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:23919" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1086" version="1" comment="Full file path to Microsoft.office.server.dll" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:281" item_field="value"/>
        <literal_component>\Microsoft Shared\web server extensions\15\ISAPI</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1138" version="1" comment="Full file path to Microsoft.office.server.native.dll" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23943" item_field="value"/>
        <literal_component>\14.0\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1390" version="2" comment="Full file path to Onfda.dll" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:281" item_field="value"/>
        <literal_component>\Microsoft Shared\web server extensions\14\BIN</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1095" version="1" comment="Var holds file location for Attendantconsole.exe" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:23492" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1463" version="1" comment="Var holds file location for communicator.exe" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:23858" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1779" version="2" comment="Var holds file location for Ogl.dll (Lync 2010 Attendee for user)" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:23843" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1822" version="1" comment="Var holds file location for Ogl.dll (for Lync 2010 attendee-admin)" datatype="string">
      <object_component object_ref="oval:org.mitre.oval:obj:23972" item_field="value"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1320" version="1" comment="Object holds the path to Exchange Server 2007" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23606" item_field="value"/>
        <literal_component>ClientAccess\Owa\Bin\DocumentViewing</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1381" version="1" comment="Variable holds the installation path to bin folder of Search server" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:24125" item_field="value"/>
        <literal_component>bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1542" version="1" comment="Variable holds the path to exchange server directory" datatype="string">
      <concat>
        <object_component object_ref="oval:org.mitre.oval:obj:23243" item_field="value"/>
        <literal_component>ClientAccess\Owa\Bin\DocumentViewing</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:834" version="1" comment="The SharePoint BIN directory" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\web server extensions\12\BIN</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1050" version="1" comment="Microsoft Shared\Web Server Extensions\14\ISAPI directory" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\Web Server Extensions\14\ISAPI</literal_component>
      </concat>
    </local_variable>
  </variables>
</oval_definitions>